Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthorizationCWE-862 × clear
HIGH 7.2 CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi… Build Of Keycloak No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-18573 A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs … Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-18218 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 8.1 CVE-2026-18214 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-18208 A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 5.5 CVE-2026-18201 Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w… Build Of Keycloak No fix yet Fix from $1,6002026-07-29 MEDIUM 6.8 CVE-2026-10609 A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d… Cluster Logging Operator Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.5 CVE-2026-26104 A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The… Enterprise Linux Mitigation only Fix from $1,6002026-02-25 HIGH 7.1 CVE-2026-26103 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut… Enterprise Linux Mitigation only Fix from $1,9502026-02-25 MEDIUM 5.3 CVE-2024-9671 A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo… 3scale Api Management Platform Mitigation only Fix from $1,6002024-10-09 CRITICAL 9.1 CVE-2023-6394 A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati… Build Of Quarkus 3.6.0+ Fix from $2,3002023-12-09 HIGH 7.5 CVE-2023-0456 A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul… Apicast 2.12.2 / 2.13.2+ Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-0923 A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making … Openshift Data Science 1.22.1-3+ Fix from $2,3002023-09-15 CRITICAL 9.8 CVE-2022-1245 A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac… Keycloak 18.0.0+ Fix from $2,3002022-07-08 HIGH 7.5 CVE-2021-3814 It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b… 3scale 2.11.0+ Fix from $1,9502022-03-25 MEDIUM 6.5 CVE-2020-10701 A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec… Libvirt 6.2.0+ Fix from $1,6002021-05-27 CRITICAL 9.1 CVE-2018-10866 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $2,3002021-05-26 HIGH 7.5 CVE-2018-10865 It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use… Certification Mitigation only Fix from $1,9502021-05-26 MEDIUM 6.5 CVE-2020-25711 A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When … Data Grid 11.0.6+ Fix from $1,6002020-12-03 HIGH 7.1 CVE-2020-10684 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a … Ansible 2.7.17 / 2.8.9+ Fix from $1,9502020-03-24 HIGH 7.1 CVE-2019-14822 A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another… Enterprise Linux 1.5.22+ Fix from $1,9502019-11-25 HIGH 7.8 CVE-2019-10167 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify … Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-10161 It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif… Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-07-30 HIGH 7.5 CVE-2019-10184 undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through reque… Undertow 2.0.23+ Fix from $1,9502019-07-25 HIGH 7.7 CVE-2019-10145 rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp… Rkt after 1.30.0 Fix from $1,9502019-06-03 HIGH 7.7 CVE-2019-10147 rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by … Rkt after 1.30.0 Fix from $1,9502019-06-03 MEDIUM 5.4 CVE-2019-3886 An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest a… Libvirt 5.3.0+ Fix from $1,6002019-04-04 HIGH 8.1 CVE-2019-3879 It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission … Virtualization 4.3.2.1+ Fix from $1,9502019-03-25 MEDIUM 5.5 CVE-2019-3835 It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou… Ansible Tower No fix yet Fix from $1,6002019-03-25