Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 6.5
CVE-2025-47711

There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific reques…

No fix yet
Fix from $1,600 2025-06-09
Enterprise Linux MEDIUM 5.5
CVE-2025-46399

A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.

No fix yet
Fix from $1,600 2025-04-23
Enterprise Linux MEDIUM 5.5
CVE-2025-46400

In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje…

No fix yet
Fix from $1,600 2025-04-23
Enterprise Linux HIGH 7.8
CVE-2025-46397

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

No fix yet
Fix from $1,950 2025-04-23
Enterprise Linux MEDIUM 5.5
CVE-2025-46398

In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.

No fix yet
Fix from $1,600 2025-04-23
Codeready Linux Builder MEDIUM 6.5
CVE-2025-2784

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. L…

No fix yet
Fix from $1,600 2025-04-03
Openshift Service Mesh HIGH 7.1
CVE-2025-0752

A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay atta…

Mitigation only
Fix from $1,950 2025-01-28
Openshift HIGH 7.5
CVE-2024-12085EPSS 9%

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length…

No fix yet
Fix from $1,950 2025-01-14
Discovery HIGH 7.5
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…

Mitigation only
Fix from $1,950 2025-01-14
3scale Api Management HIGH 7.5
CVE-2024-10295

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…

Mitigation only
Fix from $1,950 2024-10-24
Openshift Container Platform MEDIUM 6.5
CVE-2024-50311

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…

Mitigation only
Fix from $1,600 2024-10-22
Build Of Keycloak HIGH 7.3
CVE-2024-10234

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…

Mitigation only
Fix from $1,950 2024-10-22
Quay MEDIUM 5.3
CVE-2024-9683

A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…

Mitigation only
Fix from $1,600 2024-10-17
Ansible Automation Platform MEDIUM 6.1
CVE-2024-10033

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…

Mitigation only
Fix from $1,600 2024-10-16
3scale Api Management Platform MEDIUM 5.3
CVE-2024-9671

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…

Mitigation only
Fix from $1,600 2024-10-09
Build Of Keycloak MEDIUM 6.1
CVE-2024-8883

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…

Mitigation only
Fix from $1,600 2024-09-19
Enterprise Linux MEDIUM 5.5
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U…

Mitigation only
Fix from $1,600 2024-09-19
Keycloak HIGH 7.5
CVE-2023-6841

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP…

Mitigation only
Fix from $1,950 2024-09-10
Satellite CRITICAL 9.8
CVE-2024-7012

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…

Mitigation only
Fix from $2,300 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7923

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…

Mitigation only
Fix from $2,300 2024-09-04
Kroxylicious MEDIUM 5.9
CVE-2024-8285

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …

Mitigation only
Fix from $1,600 2024-08-30
Openstack Platform HIGH 8.1
CVE-2024-8007

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …

Mitigation only
Fix from $1,950 2024-08-21
Build Of Apache Camel Hawtio HIGH 7.5
CVE-2024-7885

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…

Mitigation only
Fix from $1,950 2024-08-21
Openstack Platform MEDIUM 5.0
CVE-2024-7319

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …

Mitigation only
Fix from $1,600 2024-08-02
Openshift Container Platform MEDIUM 6.5
CVE-2024-7079

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…

Mitigation only
Fix from $1,600 2024-07-24
Service Interconnect MEDIUM 5.3
CVE-2024-6535

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…

Mitigation only
Fix from $1,600 2024-07-17
Directory Server MEDIUM 6.5
CVE-2024-6237

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex…

Mitigation only
Fix from $1,600 2024-07-09
Enterprise Linux MEDIUM 6.8
CVE-2024-6505

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R…

Mitigation only
Fix from $1,600 2024-07-05
Enterprise Linux HIGH 8.1
CVE-2024-3183

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new…

Mitigation only
Fix from $1,950 2024-06-12
Satellite MEDIUM 6.2
CVE-2024-3716

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…

Mitigation only
Fix from $1,600 2024-06-05