Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Advanced Cluster Management For Kubernetes HIGH 8.2
CVE-2026-4740

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern…

No fix yet
Fix from $1,950 2026-04-07
Hardened Images MEDIUM 5.5
CVE-2026-5704

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…

No fix yet
Fix from $1,600 2026-04-06
Enterprise Linux HIGH 7.1
CVE-2026-5673

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically i…

No fix yet
Fix from $1,950 2026-04-06
Build Of Keycloak MEDIUM 5.3
CVE-2026-37977

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-…

No fix yet
Fix from $1,600 2026-04-06
Hardened Images MEDIUM 5.3
CVE-2026-3184

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the suppl…

Mitigation only
Fix from $1,600 2026-04-03
Hardened Images MEDIUM 5.5
CVE-2026-2625

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.…

Mitigation only
Fix from $1,600 2026-04-03
Build Of Keycloak HIGH 8.1
CVE-2026-4636

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows …

No fix yet
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.5
CVE-2026-4634

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessiv…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.4
CVE-2026-4282

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.3
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak MEDIUM 5.3
CVE-2026-4325

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al…

Mitigation only
Fix from $1,600 2026-04-02
Openshift HIGH 8.2
CVE-2026-35091

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit toke…

No fix yet
Fix from $1,950 2026-04-01
Openshift HIGH 7.5
CVE-2026-35092

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacke…

No fix yet
Fix from $1,950 2026-04-01
Enterprise Linux HIGH 7.5
CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation …

Mitigation only
Fix from $1,950 2026-03-31
Enterprise Linux HIGH 8.2
CVE-2026-5119

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext …

No fix yet
Fix from $1,950 2026-03-30
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28369

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28367

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28368

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…

Mitigation only
Fix from $2,300 2026-03-27
Openshift Ai HIGH 8.1
CVE-2025-12805

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed…

No fix yet
Fix from $1,950 2026-03-26
Enterprise Linux MEDIUM 6.5
CVE-2026-2239

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Phot…

No fix yet
Fix from $1,600 2026-03-26
Enterprise Linux MEDIUM 6.5
CVE-2026-2272

A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read…

No fix yet
Fix from $1,600 2026-03-26
Enterprise Linux HIGH 8.2
CVE-2026-2436

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` functio…

No fix yet
Fix from $1,950 2026-03-26
Build Of Keycloak HIGH 7.2
CVE-2026-3121

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…

Mitigation only
Fix from $1,950 2026-03-26
Openshift Container Platform MEDIUM 5.5
CVE-2026-4897

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…

Mitigation only
Fix from $1,600 2026-03-26
Hardened Images HIGH 7.8
CVE-2026-4775

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile func…

Mitigation only
Fix from $1,950 2026-03-24
Openshift Container Platform MEDIUM 6.1
CVE-2026-4647

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue o…

Mitigation only
Fix from $1,600 2026-03-23
Build Of Keycloak MEDIUM 5.8
CVE-2026-4366

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli…

Mitigation only
Fix from $1,600 2026-03-18
Build Of Keycloak HIGH 8.1
CVE-2026-2603

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…

Mitigation only
Fix from $1,950 2026-03-18
Build Of Keycloak HIGH 7.7
CVE-2026-2092

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions wh…

Mitigation only
Fix from $1,950 2026-03-18
Enterprise Linux HIGH 7.5
CVE-2026-4271

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme…

No fix yet
Fix from $1,950 2026-03-17