Vulnerability index

Browse CVEs

812 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2025-46399 A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function. Enterprise Linux No fix yet Fix from $1,6002025-04-23 MEDIUM 5.5 CVE-2025-46400 In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje… Enterprise Linux No fix yet Fix from $1,6002025-04-23 HIGH 7.8 CVE-2025-46397 A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function. Enterprise Linux No fix yet Fix from $1,9502025-04-23 MEDIUM 5.5 CVE-2025-46398 In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function. Enterprise Linux No fix yet Fix from $1,6002025-04-23 MEDIUM 6.5 CVE-2025-2784 A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. L… Codeready Linux Builder No fix yet Fix from $1,6002025-04-03 HIGH 7.1 CVE-2025-0752 A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay atta… Openshift Service Mesh Mitigation only Fix from $1,9502025-01-28 HIGH 7.5 CVE-2024-12085EPSS 9% A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length… Openshift No fix yet Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-12088 A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t… Discovery Mitigation only Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-10295 A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal… 3scale Api Management Mitigation only Fix from $1,9502024-10-24 MEDIUM 6.5 CVE-2024-50311 A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera… Openshift Container Platform Mitigation only Fix from $1,6002024-10-22 HIGH 7.3 CVE-2024-10234 A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or… Build Of Keycloak Mitigation only Fix from $1,9502024-10-22 MEDIUM 5.3 CVE-2024-9683 A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a… Quay Mitigation only Fix from $1,6002024-10-17 MEDIUM 6.1 CVE-2024-10033 A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us… Ansible Automation Platform Mitigation only Fix from $1,6002024-10-16 MEDIUM 5.3 CVE-2024-9671 A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo… 3scale Api Management Platform Mitigation only Fix from $1,6002024-10-09 MEDIUM 6.1 CVE-2024-8883 A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se… Build Of Keycloak Mitigation only Fix from $1,6002024-09-19 MEDIUM 5.5 CVE-2024-8354 A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U… Enterprise Linux Mitigation only Fix from $1,6002024-09-19 HIGH 7.5 CVE-2023-6841 A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP… Keycloak Mitigation only Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-7012 An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-7923 An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore… Satellite Mitigation only Fix from $2,3002024-09-04 MEDIUM 5.9 CVE-2024-8285 A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails … Kroxylicious Mitigation only Fix from $1,6002024-08-30 HIGH 8.1 CVE-2024-8007 A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker … Openstack Platform Mitigation only Fix from $1,9502024-08-21 HIGH 7.5 CVE-2024-7885 A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue… Build Of Apache Camel Hawtio Mitigation only Fix from $1,9502024-08-21 MEDIUM 5.0 CVE-2024-7319 An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon … Openstack Platform Mitigation only Fix from $1,6002024-08-02 MEDIUM 6.5 CVE-2024-7079 A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th… Openshift Container Platform Mitigation only Fix from $1,6002024-07-24 MEDIUM 5.3 CVE-2024-6535 A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift… Service Interconnect Mitigation only Fix from $1,6002024-07-17 MEDIUM 6.5 CVE-2024-6237 A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex… Directory Server Mitigation only Fix from $1,6002024-07-09 MEDIUM 6.8 CVE-2024-6505 A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R… Enterprise Linux Mitigation only Fix from $1,6002024-07-05 HIGH 8.1 CVE-2024-3183 A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new… Enterprise Linux Mitigation only Fix from $1,9502024-06-12 MEDIUM 6.2 CVE-2024-3716 A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce… Satellite Mitigation only Fix from $1,6002024-06-05 HIGH 8.8 CVE-2024-3622 A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati… Mirror Registry Mitigation only Fix from $1,9502024-04-25