Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-18572
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18203
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p…
Build Of Keycloak
No fix yet
HIGH 8.8
CVE-2026-59851
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ…
Hardened Images
No fix yet
HIGH 8.1
CVE-2026-3009
A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…
Build Of Keycloak
Mitigation only
MEDIUM 6.5
CVE-2025-9572
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, …
Satellite
3.16.2+
HIGH 7.5
CVE-2024-10295
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…
3scale Api Management
Mitigation only
HIGH 7.5
CVE-2022-3248
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 8.1
CVE-2023-1832
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…
Satellite
4.3.7-3+
HIGH 8.1
CVE-2023-4853
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…
Build Of Optaplanner
1.10.2 / 2.13.8+
HIGH 7.8
CVE-2023-3899
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…
Subscription Manager
1.28.39 / 1.29.37+
HIGH 7.8
CVE-2023-3027
The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 7.1
CVE-2022-2989
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data …
Openshift Container Platform
Patch available
HIGH 7.1
CVE-2022-2990
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data…
Openshift Container Platform
1.27.1+
HIGH 8.1
CVE-2022-23451
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo…
Openstack Platform
14.0.0+
CRITICAL 9.1
CVE-2022-0670
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…
Ceph Storage
5.2 / 15.2.17+
MEDIUM 6.5
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu…
Ignition
2.14.0+
MEDIUM 5.3
CVE-2022-0866
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a…
Jboss Enterprise Application Platform
26.1.1+
MEDIUM 6.5
CVE-2022-1466
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po…
Keycloak
17.0.1+
HIGH 8.8
CVE-2021-4133
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default …
Keycloak
15.1.1+
HIGH 8.1
CVE-2021-20179
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …
Certificate System
10.5.0 / 10.8.0+
HIGH 7.0
CVE-2021-20188
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c…
Openshift Container Platform
1.7.0+
MEDIUM 5.4
CVE-2020-1725
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl…
Keycloak
13.0.0+
MEDIUM 6.5
CVE-2020-25655
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…
Advanced Cluster Management For Kubernetes
Mitigation only
HIGH 8.8
CVE-2019-14843
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal…
Single Sign On
Patch available
MEDIUM 6.5
CVE-2014-0169
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.5
CVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Ovirt Engine
Mitigation only
CRITICAL 9.1
CVE-2010-2548
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Icedtea6
1.7.4+
HIGH 7.5
CVE-2019-14832
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…
Keycloak
7.0.1+
CRITICAL 9.8
CVE-2019-14813EPSS 11%
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…
Openshift Container Platform
Patch available
HIGH 7.8
CVE-2019-14811
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls…
Openshift Container Platform
9.50+