Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2026-18571
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18573
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-18570
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-18218
A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe…
Build Of Keycloak
No fix yet
HIGH 8.1
CVE-2026-18214
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18208
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme…
Build Of Keycloak
No fix yet
MEDIUM 5.5
CVE-2026-18201
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w…
Build Of Keycloak
No fix yet
MEDIUM 6.8
CVE-2026-10609
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…
Cluster Logging Operator
Mitigation only
MEDIUM 5.5
CVE-2026-26104
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The…
Enterprise Linux
Mitigation only
HIGH 7.1
CVE-2026-26103
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut…
Enterprise Linux
Mitigation only
MEDIUM 5.3
CVE-2024-9671
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…
3scale Api Management Platform
Mitigation only
CRITICAL 9.1
CVE-2023-6394
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…
Build Of Quarkus
3.6.0+
HIGH 7.5
CVE-2023-0456
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…
Apicast
2.12.2 / 2.13.2+
CRITICAL 9.8
CVE-2023-0923
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …
Openshift Data Science
1.22.1-3+
CRITICAL 9.8
CVE-2022-1245
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…
Keycloak
18.0.0+
HIGH 7.5
CVE-2021-3814
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b…
3scale
2.11.0+
MEDIUM 6.5
CVE-2020-10701
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This flaw allows read-only connec…
Libvirt
6.2.0+
CRITICAL 9.1
CVE-2018-10866
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…
Certification
Mitigation only
HIGH 7.5
CVE-2018-10865
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated use…
Certification
Mitigation only
MEDIUM 6.5
CVE-2020-25711
A flaw was found in infinispan 10 REST API, where authorization permissions are not checked while performing some server management operations. When …
Data Grid
11.0.6+
HIGH 7.1
CVE-2020-10684
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a …
Ansible
2.7.17 / 2.8.9+
HIGH 7.1
CVE-2019-14822
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another…
Enterprise Linux
1.5.22+
HIGH 7.8
CVE-2019-10167
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …
Libvirt
4.10.1 / 5.4.1+
HIGH 7.8
CVE-2019-10161
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specif…
Libvirt
4.10.1 / 5.4.1+
HIGH 7.5
CVE-2019-10184
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through reque…
Undertow
2.0.23+
HIGH 7.7
CVE-2019-10145
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` do not have seccomp…
Rkt
after 1.30.0
HIGH 7.7
CVE-2019-10147
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are not limited by …
Rkt
after 1.30.0
MEDIUM 5.4
CVE-2019-3886
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest a…
Libvirt
5.3.0+
HIGH 8.1
CVE-2019-3879
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission …
Virtualization
4.3.2.1+
MEDIUM 5.5
CVE-2019-3835
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file cou…
Ansible Tower
No fix yet