Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.6
CVE-2026-18381
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to…
Cost Management Metrics Operator
No fix yet
MEDIUM 6.8
CVE-2026-18378
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a…
Cost Management Metrics Operator
No fix yet
MEDIUM 6.8
CVE-2026-18382
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an…
Cost Management Metrics Operator
No fix yet
HIGH 7.4
CVE-2026-12992
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W…
Build Of Apicurio Registry
after 3.2
MEDIUM 6.5
CVE-2026-42965
A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ…
Openshift Container Platform
Mitigation only
MEDIUM 5.5
CVE-2026-32591
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…
Mirror Registry For Red Hat Openshift
Mitigation only
MEDIUM 6.5
CVE-2026-2377
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to …
Mirror Registry For Red Hat Openshift
Mitigation only
MEDIUM 5.8
CVE-2026-4366
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli…
Build Of Keycloak
Mitigation only
HIGH 7.5
CVE-2022-4492
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…
Build Of Quarkus
Mitigation only
HIGH 7.8
CVE-2022-3841
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…
Advanced Cluster Management For Kubernetes
Mitigation only
CRITICAL 9.1
CVE-2022-0671
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
Vscode Xml
0.19.0+
CRITICAL 9.8
CVE-2021-20325
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regress…
Enterprise Linux
Mitigation only
CRITICAL 9.0
CVE-2021-40438 KEVEPSS 100%
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP …
Enterprise Linux
Patch available
MEDIUM 5.5
CVE-2020-14327
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Functionality on the Tower server is …
Ansible Tower
3.6.5 / 3.7.2+
MEDIUM 5.3
CVE-2020-10770EPSS 70%
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_u…
Keycloak
12.0.2+
HIGH 7.1
CVE-2020-14296
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…
Cloudforms Management Engine
Mitigation only
MEDIUM 6.3
CVE-2017-7553
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the netwo…
Mobile Application Platform
after 4.4.3
MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…
Enterprise Linux Desktop
Patch available