Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2020-1699
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i…
Ceph Storage
Mitigation only
HIGH 7.0
CVE-2019-19351
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…
Openshift
Mitigation only
HIGH 7.0
CVE-2019-19355
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…
Openshift
Mitigation only
CRITICAL 9.1
CVE-2019-14887
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An…
Jboss Data Grid
Mitigation only
HIGH 7.0
CVE-2020-1706
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2019-14886
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context…
Decision Manager
Mitigation only
HIGH 8.8
CVE-2012-4512EPSS 12%
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem…
Enterprise Linux
No fix yet
HIGH 7.0
CVE-2020-1708
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2020-1700
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making mult…
Openshift Container Storage
Mitigation only
CRITICAL 9.8
CVE-2013-2060EPSS 6%
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…
Openshift
No fix yet
HIGH 7.5
CVE-2012-5626
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and…
Jboss Brms
Mitigation only
MEDIUM 6.5
CVE-2019-19339
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel…
Enterprise Linux
Mitigation only
HIGH 8.8
CVE-2019-14819
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…
Openshift Container Platform
No fix yet
MEDIUM 6.5
CVE-2019-14854
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…
Openshift Container Platform
No fix yet
MEDIUM 6.5
CVE-2014-3590
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …
Satellite
Mitigation only
MEDIUM 6.1
CVE-2014-0183
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
Subscription Asset Manager
Mitigation only
MEDIUM 5.9
CVE-2014-0245
It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, und…
Jboss Portal
Mitigation only
MEDIUM 6.5
CVE-2014-0169
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 6.3
CVE-2019-10205
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …
Quay
Mitigation only
MEDIUM 6.5
CVE-2013-0196
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me…
Openshift
No fix yet
MEDIUM 6.5
CVE-2019-19337
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse …
Ceph Storage
Mitigation only
MEDIUM 6.1
CVE-2016-1000229
swagger-ui has XSS in key names
Jboss Fuse
Mitigation only
HIGH 7.8
CVE-2012-2312
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat …
Jboss Application Server
Mitigation only
CRITICAL 9.8
CVE-2014-3699
eDeploy has RCE via cPickle deserialization of untrusted data
Edeploy
No fix yet
HIGH 8.1
CVE-2014-3701
eDeploy has tmp file race condition flaws
Edeploy
No fix yet
MEDIUM 5.5
CVE-2014-3536
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
Cloudforms Management Engine
Mitigation only
MEDIUM 5.5
CVE-2014-0241
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
Satellite
Mitigation only
CRITICAL 9.8
CVE-2014-0175
mcollective has a default password set at install
Openshift
Mitigation only
HIGH 8.8
CVE-2014-0163
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
Openshift
Mitigation only
MEDIUM 6.5
CVE-2014-0026
katello-headpin is vulnerable to CSRF in REST API
Subscription Asset Manager
No fix yet