Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2026-73433 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements… Enterprise Linux No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc… Enterprise Linux No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-18967 A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP… Build Of Keycloak No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-68743 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining … Openshift Container Platform No fix yet Fix from $1,9502026-08-04 MEDIUM 5.4 CVE-2026-18651 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t… Directory Server No fix yet Fix from $1,6002026-08-03 MEDIUM 5.5 CVE-2026-68742 A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining p… Openshift Container Platform No fix yet Fix from $1,6002026-08-03 HIGH 7.2 CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi… Build Of Keycloak No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-18572 Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18573 A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs … Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-11770 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c… Directory Server No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-15722 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c… Directory Server No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-18218 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 8.1 CVE-2026-18214 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-18215 Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-18203 A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-18208 A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-18211 A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 7.6 CVE-2026-18381 A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to… Cost Management Metrics Operator No fix yet Fix from $1,9502026-07-30 MEDIUM 6.8 CVE-2026-18378 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a… Cost Management Metrics Operator No fix yet Fix from $1,6002026-07-30 MEDIUM 6.8 CVE-2026-18382 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an… Cost Management Metrics Operator No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-18207 A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of … Build Of Keycloak No fix yet Fix from $1,6002026-07-29 MEDIUM 5.5 CVE-2026-18201 Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w… Build Of Keycloak No fix yet Fix from $1,6002026-07-29 HIGH 7.8 CVE-2026-66758 A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bi… Enterprise Linux No fix yet Fix from $1,9502026-07-27 HIGH 7.1 CVE-2026-66759 A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data… Enterprise Linux No fix yet Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-66757 A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image … Enterprise Linux No fix yet Fix from $1,6002026-07-27 MEDIUM 6.5 CVE-2026-17059 A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem… Build Of Keycloak No fix yet Fix from $1,6002026-07-24 HIGH 8.8 CVE-2026-59851 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ… Hardened Images No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-59849 A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when … Hardened Images No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-59850 A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data … Hardened Images No fix yet Fix from $1,9502026-07-21