Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2014-3656
JBoss KeyCloak: XSS in login-status-iframe.html
Jboss Keycloak
No fix yet
HIGH 7.5
CVE-2013-1793
openstack-utils openstack-db has insecure password creation
Openstack
Mitigation only
CRITICAL 9.8
CVE-2019-14910
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
Keycloak
Mitigation only
MEDIUM 5.5
CVE-2013-0163
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Openshift
Mitigation only
HIGH 8.3
CVE-2019-14909
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…
Keycloak
Mitigation only
HIGH 8.1
CVE-2013-2103
OpenShift cartridge allows remote URL retrieval
Openshift
Mitigation only
MEDIUM 5.4
CVE-2013-2101
Katello has multiple XSS issues in various entities
Satellite
No fix yet
HIGH 8.4
CVE-2019-14890
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from …
Ansible Tower
Mitigation only
MEDIUM 6.5
CVE-2011-3609
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …
Jboss Application Server
Mitigation only
MEDIUM 5.4
CVE-2011-3606
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…
Jboss Application Server
Mitigation only
MEDIUM 6.5
CVE-2015-5694
Designate does not enforce the DNS protocol limit concerning record set sizes
Enterprise Linux Openstack Platform
Mitigation only
CRITICAL 9.8
CVE-2014-3585
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Redhat Upgrade Tool
Mitigation only
MEDIUM 6.5
CVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Ovirt Engine
Mitigation only
MEDIUM 5.4
CVE-2018-10854
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…
Cloudforms Management Engine
Mitigation only
CRITICAL 9.8
CVE-2012-3460
cumin: At installation postgresql database user created without password
Enterprise Mrg
Mitigation only
MEDIUM 5.5
CVE-2012-6136
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
Tuned
Mitigation only
HIGH 7.8
CVE-2014-0023
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
Openshift
Mitigation only
MEDIUM 5.9
CVE-2014-8167
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
Enterprise Virtualization
Mitigation only
MEDIUM 6.5
CVE-2019-14824
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2019-3866
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…
Openstack Mistral
Mitigation only
MEDIUM 5.5
CVE-2014-8181
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2013-4280
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
Virtual Desktop Server Manager
No fix yet
MEDIUM 5.5
CVE-2013-4423
CloudForms stores user passwords in recoverable format
Cloudforms
Mitigation only
MEDIUM 5.5
CVE-2013-4518
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
Update Infrastructure
No fix yet
HIGH 7.5
CVE-2019-6470EPSS 9%
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …
Enterprise Linux
No fix yet
HIGH 7.3
CVE-2013-0165
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Openshift
Mitigation only
MEDIUM 6.1
CVE-2013-0186
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
Cloudforms
Mitigation only
MEDIUM 5.9
CVE-2013-2255
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…
Openstack
Mitigation only
CRITICAL 9.8
CVE-2019-10202EPSS 5%
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2019-10176
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found …
Openshift Container Platform
Mitigation only