Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2025-46399
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2025-46400
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulation via read_arcobje…
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2025-46397
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2025-46398
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_objects function.
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2025-2784
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. L…
Codeready Linux Builder
No fix yet
HIGH 7.1
CVE-2025-0752
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay atta…
Openshift Service Mesh
Mitigation only
HIGH 7.5
CVE-2024-12085EPSS 9%
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length…
Openshift
No fix yet
HIGH 7.5
CVE-2024-12088
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…
Discovery
Mitigation only
HIGH 7.5
CVE-2024-10295
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…
3scale Api Management
Mitigation only
MEDIUM 6.5
CVE-2024-50311
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…
Openshift Container Platform
Mitigation only
HIGH 7.3
CVE-2024-10234
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…
Build Of Keycloak
Mitigation only
MEDIUM 5.3
CVE-2024-9683
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…
Quay
Mitigation only
MEDIUM 6.1
CVE-2024-10033
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…
Ansible Automation Platform
Mitigation only
MEDIUM 5.3
CVE-2024-9671
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…
3scale Api Management Platform
Mitigation only
MEDIUM 6.1
CVE-2024-8883
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…
Build Of Keycloak
Mitigation only
MEDIUM 5.5
CVE-2024-8354
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2023-6841
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP…
Keycloak
Mitigation only
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
MEDIUM 5.9
CVE-2024-8285
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …
Kroxylicious
Mitigation only
HIGH 8.1
CVE-2024-8007
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …
Openstack Platform
Mitigation only
HIGH 7.5
CVE-2024-7885
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…
Build Of Apache Camel Hawtio
Mitigation only
MEDIUM 5.0
CVE-2024-7319
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …
Openstack Platform
Mitigation only
MEDIUM 6.5
CVE-2024-7079
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…
Openshift Container Platform
Mitigation only
MEDIUM 5.3
CVE-2024-6535
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…
Service Interconnect
Mitigation only
MEDIUM 6.5
CVE-2024-6237
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex…
Directory Server
Mitigation only
MEDIUM 6.8
CVE-2024-6505
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R…
Enterprise Linux
Mitigation only
HIGH 8.1
CVE-2024-3183
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new…
Enterprise Linux
Mitigation only
MEDIUM 6.2
CVE-2024-3716
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…
Satellite
Mitigation only
HIGH 8.8
CVE-2024-3622
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati…
Mirror Registry
Mitigation only