Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-4740 A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern… Advanced Cluster Management For Kubernetes No fix yet Fix from $1,9502026-04-07 MEDIUM 5.5 CVE-2026-5704 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu… Hardened Images No fix yet Fix from $1,6002026-04-06 HIGH 7.1 CVE-2026-5673 A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically i… Enterprise Linux No fix yet Fix from $1,9502026-04-06 MEDIUM 5.3 CVE-2026-37977 A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-… Build Of Keycloak No fix yet Fix from $1,6002026-04-06 MEDIUM 5.3 CVE-2026-3184 A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the suppl… Hardened Images Mitigation only Fix from $1,6002026-04-03 MEDIUM 5.5 CVE-2026-2625 A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.… Hardened Images Mitigation only Fix from $1,6002026-04-03 HIGH 8.1 CVE-2026-4636 A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows … Build Of Keycloak No fix yet Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-4634 A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessiv… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 HIGH 7.4 CVE-2026-4282 A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 HIGH 7.3 CVE-2026-3872 A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-4325 A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al… Build Of Keycloak Mitigation only Fix from $1,6002026-04-02 HIGH 8.2 CVE-2026-35091 A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit toke… Openshift No fix yet Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-35092 A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacke… Openshift No fix yet Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-5201 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation … Enterprise Linux Mitigation only Fix from $1,9502026-03-31 HIGH 8.2 CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext … Enterprise Linux No fix yet Fix from $1,9502026-03-30 CRITICAL 9.1 CVE-2026-28369 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28367 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28368 A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 HIGH 8.1 CVE-2025-12805 A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed… Openshift Ai No fix yet Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-2239 A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Phot… Enterprise Linux No fix yet Fix from $1,6002026-03-26 MEDIUM 6.5 CVE-2026-2272 A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read… Enterprise Linux No fix yet Fix from $1,6002026-03-26 HIGH 8.2 CVE-2026-2436 A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` functio… Enterprise Linux No fix yet Fix from $1,9502026-03-26 HIGH 7.2 CVE-2026-3121 A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to… Build Of Keycloak Mitigation only Fix from $1,9502026-03-26 MEDIUM 5.5 CVE-2026-4897 A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set… Openshift Container Platform Mitigation only Fix from $1,6002026-03-26 HIGH 7.8 CVE-2026-4775 A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile func… Hardened Images Mitigation only Fix from $1,9502026-03-24 MEDIUM 6.1 CVE-2026-4647 A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue o… Openshift Container Platform Mitigation only Fix from $1,6002026-03-23 MEDIUM 5.8 CVE-2026-4366 A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli… Build Of Keycloak Mitigation only Fix from $1,6002026-03-18 HIGH 8.1 CVE-2026-2603 A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I… Build Of Keycloak Mitigation only Fix from $1,9502026-03-18 HIGH 7.7 CVE-2026-2092 A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions wh… Build Of Keycloak Mitigation only Fix from $1,9502026-03-18 HIGH 7.5 CVE-2026-4271 A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme… Enterprise Linux No fix yet Fix from $1,9502026-03-17