Vulnerability index

Browse CVEs

817 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Directory Server MEDIUM 6.5
CVE-2024-6237

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex…

Mitigation only
Fix from $1,600 2024-07-09
Enterprise Linux MEDIUM 6.8
CVE-2024-6505

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R…

Mitigation only
Fix from $1,600 2024-07-05
Enterprise Linux HIGH 8.1
CVE-2024-3183

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new…

Mitigation only
Fix from $1,950 2024-06-12
Satellite MEDIUM 6.2
CVE-2024-3716

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…

Mitigation only
Fix from $1,600 2024-06-05
Mirror Registry HIGH 8.8
CVE-2024-3622

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati…

Mitigation only
Fix from $1,950 2024-04-25
Mirror Registry MEDIUM 6.5
CVE-2024-3623

A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of th…

Mitigation only
Fix from $1,600 2024-04-25
Openstack Platform MEDIUM 5.5
CVE-2023-6725

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were impr…

Mitigation only
Fix from $1,600 2024-03-15
Openshift Container Platform MEDIUM 6.5
CVE-2024-1725

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated atta…

Mitigation only
Fix from $1,600 2024-03-07
Keycloak MEDIUM 5.3
CVE-2024-1722

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

Mitigation only
Fix from $1,600 2024-02-29
Undertow MEDIUM 5.3
CVE-2024-1459

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP reques…

Mitigation only
Fix from $1,600 2024-02-12
Codeready Linux Builder Eus HIGH 7.5
CVE-2023-6356

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…

Mitigation only
Fix from $1,950 2024-02-07
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-4503

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created …

Mitigation only
Fix from $1,950 2024-02-06
Enterprise Linux HIGH 7.5
CVE-2023-50781

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which ma…

Mitigation only
Fix from $1,950 2024-02-05
Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Enterprise Linux MEDIUM 5.9
CVE-2023-5992

A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in th…

No fix yet
Fix from $1,600 2024-01-31
Enterprise Linux MEDIUM 6.8
CVE-2023-4001

An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains…

Mitigation only
Fix from $1,600 2024-01-15
Openshift Container Platform HIGH 7.5
CVE-2023-6476

A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get a…

Mitigation only
Fix from $1,950 2024-01-09
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-3171

A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources…

Mitigation only
Fix from $1,950 2023-12-27
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4641

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …

Mitigation only
Fix from $1,600 2023-12-27
Single Sign On HIGH 8.1
CVE-2023-2585

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validatio…

Mitigation only
Fix from $1,950 2023-12-21
Keycloak MEDIUM 6.1
CVE-2023-6927

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo…

Mitigation only
Fix from $1,600 2023-12-18
Ansible Automation Platform MEDIUM 6.3
CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make …

Mitigation only
Fix from $1,600 2023-12-18
Jboss Enterprise Application Platform HIGH 7.5
CVE-2023-5379

A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error…

Mitigation only
Fix from $1,950 2023-12-12
Enterprise Linux MEDIUM 5.4
CVE-2023-6710

A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the…

Mitigation only
Fix from $1,600 2023-12-12
Build Of Quarkus MEDIUM 5.3
CVE-2023-6393

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial…

Mitigation only
Fix from $1,600 2023-12-06
Ansible Automation Platform MEDIUM 6.5
CVE-2023-5189

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …

No fix yet
Fix from $1,600 2023-11-14
3scale Api Management MEDIUM 5.5
CVE-2023-4910

A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens…

Mitigation only
Fix from $1,600 2023-11-06
Enterprise Linux HIGH 7.5
CVE-2023-46847EPSS 88%

Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to he…

Mitigation only
Fix from $1,950 2023-11-03
Advanced Cluster Management For Kubernetes HIGH 7.5
CVE-2022-3248

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…

Mitigation only
Fix from $1,950 2023-10-05
Openshift Container Platform MEDIUM 5.3
CVE-2022-4145

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, e…

Mitigation only
Fix from $1,600 2023-10-05