Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-3633 A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary head… Enterprise Linux No fix yet Fix from $1,6002026-03-17 MEDIUM 6.5 CVE-2026-3634 A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequ… Enterprise Linux No fix yet Fix from $1,6002026-03-17 MEDIUM 5.5 CVE-2026-3632 A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly val… Enterprise Linux No fix yet Fix from $1,6002026-03-17 HIGH 7.1 CVE-2026-3441 A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an atta… Openshift Container Platform Mitigation only Fix from $1,9502026-03-16 HIGH 7.1 CVE-2026-3442 A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker comp… Openshift Container Platform No fix yet Fix from $1,9502026-03-16 MEDIUM 6.4 CVE-2025-8766 A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c… Openshift Data Foundation Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2025-57849 A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable … Fuse Mitigation only Fix from $1,6002026-03-13 HIGH 7.3 CVE-2026-3099 A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued no… Enterprise Linux No fix yet Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-3047 A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider … Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-3009 A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even… Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2025-12801 A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi… Openshift Container Platform Mitigation only Fix from $1,6002026-03-04 MEDIUM 6.5 CVE-2026-3118 A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation… Developer Hub Mitigation only Fix from $1,6002026-02-25 MEDIUM 5.5 CVE-2026-26104 A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The… Enterprise Linux Mitigation only Fix from $1,6002026-02-25 HIGH 7.1 CVE-2026-26103 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut… Enterprise Linux Mitigation only Fix from $1,9502026-02-25 MEDIUM 5.3 CVE-2026-2443 A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the librar… Enterprise Linux Mitigation only Fix from $1,6002026-02-13 CRITICAL 9.8 CVE-2026-1709EPSS 5% A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.… Enterprise Linux Mitigation only Fix from $2,3002026-02-06 MEDIUM 6.5 CVE-2026-1801 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so… Enterprise Linux Mitigation only Fix from $1,6002026-02-03 MEDIUM 5.8 CVE-2026-1539 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT… Enterprise Linux Mitigation only Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-1536 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq… Enterprise Linux No fix yet Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-1467 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro… Enterprise Linux No fix yet Fix from $1,6002026-01-27 HIGH 7.7 CVE-2025-13601 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the … Codeready Linux Builder No fix yet Fix from $1,9502025-11-26 MEDIUM 5.3 CVE-2025-8419 A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send s… Keycloak Mitigation only Fix from $1,6002025-08-06 MEDIUM 6.5 CVE-2025-7784 A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use… Build Of Keycloak Mitigation only Fix from $1,6002025-07-18 HIGH 7.5 CVE-2025-7424 A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion du… Openshift Container Platform Mitigation only Fix from $1,9502025-07-10 HIGH 8.2 CVE-2025-32990 A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads ce… Openshift Container Platform Mitigation only Fix from $1,9502025-07-10 MEDIUM 5.3 CVE-2025-32989 A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten… Openshift Container Platform Mitigation only Fix from $1,6002025-07-10 MEDIUM 5.3 CVE-2025-6920 A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf… Ai Inference Server Mitigation only Fix from $1,6002025-07-01 MEDIUM 5.5 CVE-2025-5731 A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in … Data Grid Mitigation only Fix from $1,6002025-06-26 HIGH 7.5 CVE-2025-6021 A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. … Jboss Core Services No fix yet Fix from $1,9502025-06-12 MEDIUM 6.5 CVE-2025-47711 There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific reques… Enterprise Linux No fix yet Fix from $1,6002025-06-09