Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Hardened Images HIGH 7.5
CVE-2026-59847

A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al…

No fix yet
Fix from $1,950 2026-07-21
Hardened Images MEDIUM 5.3
CVE-2026-59848

A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing …

No fix yet
Fix from $1,600 2026-07-21
Hardened Images MEDIUM 5.9
CVE-2026-59845

A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b…

No fix yet
Fix from $1,600 2026-07-21
Hardened Images MEDIUM 6.5
CVE-2026-59843

A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write…

No fix yet
Fix from $1,600 2026-07-21
Hardened Images MEDIUM 6.5
CVE-2026-59844

A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser…

No fix yet
Fix from $1,600 2026-07-21
Hardened Images MEDIUM 5.3
CVE-2026-59842

A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copie…

No fix yet
Fix from $1,600 2026-07-21
Hardened Images HIGH 7.3
CVE-2026-15370

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack…

No fix yet
Fix from $1,950 2026-07-21
Build Of Keycloak MEDIUM 6.5
CVE-2026-16104

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 6.5
CVE-2026-16108

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 5.4
CVE-2026-16093

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authe…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 5.9
CVE-2026-16089

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not prop…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 5.5
CVE-2026-15943

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated a…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak HIGH 8.1
CVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…

No fix yet
Fix from $1,950 2026-07-16
Openshift Ai MEDIUM 6.5
CVE-2026-15154

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (R…

Mitigation only
Fix from $1,600 2026-07-08
Directory Server MEDIUM 5.3
CVE-2026-14940

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted…

Mitigation only
Fix from $1,600 2026-07-07
Enterprise Linux HIGH 7.8
CVE-2026-58384

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table…

Mitigation only
Fix from $1,950 2026-07-07
Enterprise Linux MEDIUM 5.5
CVE-2026-59089

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color …

No fix yet
Fix from $1,600 2026-07-06
Enterprise Linux HIGH 7.8
CVE-2026-58380

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null termin…

Mitigation only
Fix from $1,950 2026-07-06
Build Of Keycloak MEDIUM 6.5
CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role …

No fix yet
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-12388

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is …

Mitigation only
Fix from $1,600 2026-06-30
Enterprise Linux MEDIUM 6.4
CVE-2026-12610

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory …

Mitigation only
Fix from $1,600 2026-06-30
Openshift Dev Spaces HIGH 8.8
CVE-2026-12856

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Mark…

Mitigation only
Fix from $1,950 2026-06-29
Enterprise Linux MEDIUM 5.1
CVE-2026-57965

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This…

Mitigation only
Fix from $1,600 2026-06-29
Satellite MEDIUM 6.2
CVE-2026-9073

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication …

Mitigation only
Fix from $1,600 2026-06-23
Satellite HIGH 7.8
CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad…

Mitigation only
Fix from $1,950 2026-06-23
Enterprise Linux MEDIUM 6.5
CVE-2026-11820

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 5.5
CVE-2026-11819

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from …

Mitigation only
Fix from $1,600 2026-06-23
Cluster Logging Operator MEDIUM 6.8
CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 6.1
CVE-2026-55655

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible…

Mitigation only
Fix from $1,600 2026-06-23
Hardened Images MEDIUM 6.5
CVE-2026-55653

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path…

No fix yet
Fix from $1,600 2026-06-23