Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Server-Side Request Forgery (SSRF)CWE-918 × clear
Cost Management Metrics Operator HIGH 7.6
CVE-2026-18381

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to…

No fix yet
Fix from $1,950 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18378

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a…

No fix yet
Fix from $1,600 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18382

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an…

No fix yet
Fix from $1,600 2026-07-30
Build Of Apicurio Registry HIGH 7.4
CVE-2026-12992

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W…

Fix: after 3.2
Fix from $1,950 2026-06-25
Openshift Container Platform MEDIUM 6.5
CVE-2026-42965

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ…

Mitigation only
Fix from $1,600 2026-05-29
Mirror Registry For Red Hat Openshift MEDIUM 5.5
CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…

Mitigation only
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 6.5
CVE-2026-2377

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to …

Mitigation only
Fix from $1,600 2026-04-08
Build Of Keycloak MEDIUM 5.8
CVE-2026-4366

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli…

Mitigation only
Fix from $1,600 2026-03-18
Build Of Quarkus HIGH 7.5
CVE-2022-4492

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…

Mitigation only
Fix from $1,950 2023-02-23
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2022-3841

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…

Mitigation only
Fix from $1,950 2023-01-13
Vscode Xml CRITICAL 9.1
CVE-2022-0671

A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

Fix: 0.19.0+
Fix from $2,300 2022-02-18
Enterprise Linux CRITICAL 9.8
CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…

Mitigation only
Fix from $2,300 2022-02-18
Enterprise Linux CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …

Patch available
Fix from $2,300 2021-09-16
Ansible Tower MEDIUM 5.5
CVE-2020-14327

A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is …

Fix: 3.6.5 / 3.7.2+
Fix from $1,600 2021-05-27
Keycloak MEDIUM 5.3
CVE-2020-10770EPSS 70%

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…

Fix: 12.0.2+
Fix from $1,600 2020-12-15
Cloudforms Management Engine HIGH 7.1
CVE-2020-14296

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…

Mitigation only
Fix from $1,950 2020-08-11
Mobile Application Platform MEDIUM 6.3
CVE-2017-7553

The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…

Fix: after 4.4.3
Fix from $1,600 2017-09-29
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…

Patch available
Fix from $1,600 2016-05-05