Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 6.5
CVE-2026-3633

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary head…

No fix yet
Fix from $1,600 2026-03-17
Enterprise Linux MEDIUM 6.5
CVE-2026-3634

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequ…

No fix yet
Fix from $1,600 2026-03-17
Enterprise Linux MEDIUM 5.5
CVE-2026-3632

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly val…

No fix yet
Fix from $1,600 2026-03-17
Openshift Container Platform HIGH 7.1
CVE-2026-3441

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an atta…

Mitigation only
Fix from $1,950 2026-03-16
Openshift Container Platform HIGH 7.1
CVE-2026-3442

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker comp…

No fix yet
Fix from $1,950 2026-03-16
Openshift Data Foundation MEDIUM 6.4
CVE-2025-8766

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-03-13
Fuse MEDIUM 6.4
CVE-2025-57849

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable …

Mitigation only
Fix from $1,600 2026-03-13
Enterprise Linux HIGH 7.3
CVE-2026-3099

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued no…

No fix yet
Fix from $1,950 2026-03-12
Build Of Keycloak HIGH 8.8
CVE-2026-3047

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider …

Mitigation only
Fix from $1,950 2026-03-05
Build Of Keycloak HIGH 8.1
CVE-2026-3009

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…

Mitigation only
Fix from $1,950 2026-03-05
Openshift Container Platform MEDIUM 6.5
CVE-2025-12801

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi…

Mitigation only
Fix from $1,600 2026-03-04
Developer Hub MEDIUM 6.5
CVE-2026-3118

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux MEDIUM 5.5
CVE-2026-26104

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux HIGH 7.1
CVE-2026-26103

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut…

Mitigation only
Fix from $1,950 2026-02-25
Enterprise Linux MEDIUM 5.3
CVE-2026-2443

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the librar…

Mitigation only
Fix from $1,600 2026-02-13
Enterprise Linux CRITICAL 9.8
CVE-2026-1709EPSS 5%

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.…

Mitigation only
Fix from $2,300 2026-02-06
Enterprise Linux MEDIUM 6.5
CVE-2026-1801

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so…

Mitigation only
Fix from $1,600 2026-02-03
Enterprise Linux MEDIUM 5.8
CVE-2026-1539

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT…

Mitigation only
Fix from $1,600 2026-01-28
Enterprise Linux MEDIUM 5.3
CVE-2026-1536

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq…

No fix yet
Fix from $1,600 2026-01-28
Enterprise Linux MEDIUM 5.3
CVE-2026-1467

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro…

No fix yet
Fix from $1,600 2026-01-27
Codeready Linux Builder HIGH 7.7
CVE-2025-13601

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the …

No fix yet
Fix from $1,950 2025-11-26
Keycloak MEDIUM 5.3
CVE-2025-8419

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send s…

Mitigation only
Fix from $1,600 2025-08-06
Build Of Keycloak MEDIUM 6.5
CVE-2025-7784

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use…

Mitigation only
Fix from $1,600 2025-07-18
Openshift Container Platform HIGH 7.5
CVE-2025-7424

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion du…

Mitigation only
Fix from $1,950 2025-07-10
Openshift Container Platform HIGH 8.2
CVE-2025-32990

A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads ce…

Mitigation only
Fix from $1,950 2025-07-10
Openshift Container Platform MEDIUM 5.3
CVE-2025-32989

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten…

Mitigation only
Fix from $1,600 2025-07-10
Ai Inference Server MEDIUM 5.3
CVE-2025-6920

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf…

Mitigation only
Fix from $1,600 2025-07-01
Data Grid MEDIUM 5.5
CVE-2025-5731

A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in …

Mitigation only
Fix from $1,600 2025-06-26
Jboss Core Services HIGH 7.5
CVE-2025-6021

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. …

No fix yet
Fix from $1,950 2025-06-12
Enterprise Linux MEDIUM 6.5
CVE-2025-47711

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific reques…

No fix yet
Fix from $1,600 2025-06-09