Vulnerability index

Browse CVEs

815 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.5
CVE-2023-2295

A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptabl…

Mitigation only
Fix from $1,950 2023-05-17
Enterprise Linux HIGH 8.8
CVE-2023-2203

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers …

Mitigation only
Fix from $1,950 2023-05-17
Enterprise Linux HIGH 7.8
CVE-2023-2491

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el ca…

Mitigation only
Fix from $1,950 2023-05-17
Openstack MEDIUM 6.5
CVE-2023-2088

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, au…

No fix yet
Fix from $1,600 2023-05-12
Device Mapper Multipath HIGH 7.8
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in…

Mitigation only
Fix from $1,950 2023-03-29
Keycloak Node.js Adapter MEDIUM 6.1
CVE-2022-2237

A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio…

Mitigation only
Fix from $1,600 2023-03-27
Enterprise Linux MEDIUM 6.8
CVE-2023-0778

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a syml…

Mitigation only
Fix from $1,600 2023-03-27
Ceph Storage MEDIUM 6.5
CVE-2023-0056

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated r…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Ceph Storage MEDIUM 6.5
CVE-2022-3854

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash…

Mitigation only
Fix from $1,600 2023-03-06
Codeready Linux Builder HIGH 8.8
CVE-2019-8720 KEV

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.…

Mitigation only
Fix from $1,950 2023-03-06
Directory Server MEDIUM 5.5
CVE-2023-1055

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib…

Mitigation only
Fix from $1,600 2023-02-27
Build Of Quarkus HIGH 7.5
CVE-2022-4492

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…

Mitigation only
Fix from $1,950 2023-02-23
Openshift MEDIUM 6.3
CVE-2023-0229

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged …

Mitigation only
Fix from $1,600 2023-01-26
Openstack MEDIUM 5.9
CVE-2022-3100

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

Mitigation only
Fix from $1,600 2023-01-18
Openshift MEDIUM 5.3
CVE-2023-0296

The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Ev…

Mitigation only
Fix from $1,600 2023-01-17
Ceph HIGH 7.8
CVE-2022-3650

A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump,…

No fix yet
Fix from $1,950 2023-01-17
Keycloak CRITICAL 9.1
CVE-2022-3782EPSS 6%

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…

Mitigation only
Fix from $2,300 2023-01-13
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2022-3841

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…

Mitigation only
Fix from $1,950 2023-01-13
Wildfly Elytron HIGH 7.4
CVE-2022-3143

wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equ…

Mitigation only
Fix from $1,950 2023-01-13
Keycloak MEDIUM 6.5
CVE-2023-0105

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker …

Mitigation only
Fix from $1,600 2023-01-13
Openstack HIGH 8.8
CVE-2022-38065

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functio…

No fix yet
Fix from $1,950 2022-12-21
Openshift HIGH 7.4
CVE-2022-3259

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

Mitigation only
Fix from $1,950 2022-12-09
Openshift HIGH 8.1
CVE-2022-3262

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw a…

Mitigation only
Fix from $1,950 2022-12-08
Ansible Automation Platform MEDIUM 5.5
CVE-2022-3644

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the…

No fix yet
Fix from $1,600 2022-10-25
Virtualization MEDIUM 6.5
CVE-2022-2805

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attac…

Mitigation only
Fix from $1,600 2022-10-19
3scale Api Management HIGH 8.8
CVE-2022-1414

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s…

Mitigation only
Fix from $1,950 2022-10-19
Decision Manager HIGH 8.8
CVE-2019-14841

A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to …

Mitigation only
Fix from $1,950 2022-10-17
Decision Manager HIGH 7.5
CVE-2019-14840

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

No fix yet
Fix from $1,950 2022-10-17