Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Directory Server MEDIUM 5.0
CVE-2026-11791

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information…

Mitigation only
Fix from $1,600 2026-06-18
Enterprise Linux HIGH 8.1
CVE-2026-1767

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could…

No fix yet
Fix from $1,950 2026-06-16
Enterprise Linux MEDIUM 6.1
CVE-2026-1766

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This…

No fix yet
Fix from $1,600 2026-06-16
Enterprise Linux MEDIUM 5.6
CVE-2026-1764

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v…

No fix yet
Fix from $1,600 2026-06-16
Directory Server MEDIUM 6.5
CVE-2026-11789

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a craf…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server HIGH 7.5
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…

Mitigation only
Fix from $1,950 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11786

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server MEDIUM 6.3
CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a he…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11611

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c…

Mitigation only
Fix from $1,600 2026-06-08
Openshift Container Platform HIGH 8.8
CVE-2026-1784

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on…

Mitigation only
Fix from $1,950 2026-06-02
Openshift Container Platform MEDIUM 5.0
CVE-2026-10533

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet…

Mitigation only
Fix from $1,600 2026-06-01
Openshift Container Platform HIGH 7.5
CVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…

Mitigation only
Fix from $1,950 2026-05-29
Openshift Container Platform MEDIUM 6.5
CVE-2026-42965

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ…

Mitigation only
Fix from $1,600 2026-05-29
Build Of Keycloak MEDIUM 6.8
CVE-2026-9802

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal t…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak MEDIUM 5.3
CVE-2026-9803

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specia…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 7.3
CVE-2026-9795

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo…

Mitigation only
Fix from $1,950 2026-05-28
Build Of Keycloak MEDIUM 6.5
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulne…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 7.5
CVE-2026-9793

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim…

Mitigation only
Fix from $1,950 2026-05-28
Build Of Keycloak MEDIUM 6.5
CVE-2026-9792

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (cli…

No fix yet
Fix from $1,600 2026-05-28
Build Of Keycloak MEDIUM 5.3
CVE-2026-9794

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAM…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 8.8
CVE-2026-9704

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web…

Mitigation only
Fix from $1,950 2026-05-27
Openshift Container Platform MEDIUM 6.5
CVE-2026-2340

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of…

Mitigation only
Fix from $1,600 2026-05-27
Hardened Images HIGH 7.8
CVE-2026-48864

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files du…

No fix yet
Fix from $1,950 2026-05-26
Build Of Keycloak HIGH 8.1
CVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit…

Mitigation only
Fix from $1,950 2026-05-20
Directory Server HIGH 7.5
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont…

Mitigation only
Fix from $1,950 2026-05-20
Build Of Keycloak MEDIUM 5.4
CVE-2026-8922

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC)…

Mitigation only
Fix from $1,600 2026-05-19
Hardened Images HIGH 7.5
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The com…

Mitigation only
Fix from $1,950 2026-05-18
Hardened Images CRITICAL 9.8
CVE-2026-42010

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…

Mitigation only
Fix from $2,300 2026-05-07
Enterprise Linux CRITICAL 9.1
CVE-2026-34000

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…

Mitigation only
Fix from $2,300 2026-05-05
Enterprise Linux CRITICAL 9.1
CVE-2026-34002

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…

Mitigation only
Fix from $2,300 2026-05-05