Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2026-11791 A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information… Directory Server Mitigation only Fix from $1,6002026-06-18 HIGH 8.1 CVE-2026-1767 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could… Enterprise Linux No fix yet Fix from $1,9502026-06-16 MEDIUM 6.1 CVE-2026-1766 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This… Enterprise Linux No fix yet Fix from $1,6002026-06-16 MEDIUM 5.6 CVE-2026-1764 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v… Enterprise Linux No fix yet Fix from $1,6002026-06-16 MEDIUM 6.5 CVE-2026-11789 A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a craf… Directory Server Mitigation only Fix from $1,6002026-06-09 HIGH 7.5 CVE-2026-11788 A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing… Directory Server Mitigation only Fix from $1,9502026-06-09 MEDIUM 6.5 CVE-2026-11786 A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon… Directory Server Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.3 CVE-2026-11787 A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a he… Directory Server Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11611 A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c… Directory Server Mitigation only Fix from $1,6002026-06-08 HIGH 8.8 CVE-2026-1784 The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on… Openshift Container Platform Mitigation only Fix from $1,9502026-06-02 MEDIUM 5.0 CVE-2026-10533 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet… Openshift Container Platform Mitigation only Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-46579 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli… Openshift Container Platform Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-42965 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ… Openshift Container Platform Mitigation only Fix from $1,6002026-05-29 MEDIUM 6.8 CVE-2026-9802 A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal t… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-9803 A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specia… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 7.3 CVE-2026-9795 A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-9796 A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulne… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 7.5 CVE-2026-9793 A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-9792 A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (cli… Build Of Keycloak No fix yet Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-9794 A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAM… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 8.8 CVE-2026-9704 A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web… Build Of Keycloak Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-2340 A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of… Openshift Container Platform Mitigation only Fix from $1,6002026-05-27 HIGH 7.8 CVE-2026-48864 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files du… Hardened Images No fix yet Fix from $1,9502026-05-26 HIGH 8.1 CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit… Build Of Keycloak Mitigation only Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont… Directory Server Mitigation only Fix from $1,9502026-05-20 MEDIUM 5.4 CVE-2026-8922 A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC)… Build Of Keycloak Mitigation only Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-42009 A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The com… Hardened Images Mitigation only Fix from $1,9502026-05-18 CRITICAL 9.8 CVE-2026-42010 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch… Hardened Images Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-34000 A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()… Enterprise Linux Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.1 CVE-2026-34002 A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a… Enterprise Linux Mitigation only Fix from $2,3002026-05-05