Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Platform MEDIUM 6.5
CVE-2024-50311

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…

Mitigation only
Fix from $1,600 2024-10-22
Openshift Container Platform MEDIUM 5.3
CVE-2024-50312

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retri…

Patch available
Fix from $1,600 2024-10-22
Build Of Keycloak HIGH 7.3
CVE-2024-10234

A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…

Mitigation only
Fix from $1,950 2024-10-22
Quay MEDIUM 5.3
CVE-2024-9683

A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…

Mitigation only
Fix from $1,600 2024-10-17
Ansible Automation Platform MEDIUM 6.1
CVE-2024-10033

A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…

Mitigation only
Fix from $1,600 2024-10-16
Openshift Container Platform MEDIUM 6.5
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…

Patch available
Fix from $1,600 2024-10-15
3scale Api Management Platform MEDIUM 5.3
CVE-2024-9671

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…

Mitigation only
Fix from $1,600 2024-10-09
Build Of Keycloak MEDIUM 6.1
CVE-2024-8883

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…

Mitigation only
Fix from $1,600 2024-09-19
Enterprise Linux MEDIUM 5.5
CVE-2024-8354

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U…

Mitigation only
Fix from $1,600 2024-09-19
Keycloak HIGH 7.5
CVE-2023-6841

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP…

Mitigation only
Fix from $1,950 2024-09-10
Keycloak HIGH 7.1
CVE-2024-7341

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time…

Fix: 7.6.10 / 22.0.12+
Fix from $1,950 2024-09-09
Build Of Keycloak MEDIUM 6.1
CVE-2024-7260

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…

Fix: 24.0.7+
Fix from $1,600 2024-09-09
Satellite CRITICAL 9.8
CVE-2024-7012

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…

Mitigation only
Fix from $2,300 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7923

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…

Mitigation only
Fix from $2,300 2024-09-04
Keycloak MEDIUM 6.5
CVE-2024-4629

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By ini…

Fix: 7.6.10 / 22.012+
Fix from $1,600 2024-09-03
Kroxylicious MEDIUM 5.9
CVE-2024-8285

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …

Mitigation only
Fix from $1,600 2024-08-30
Libvirt MEDIUM 6.2
CVE-2024-8235

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where all…

Fix: 10.7.0+
Fix from $1,600 2024-08-30
Openstack Platform HIGH 8.1
CVE-2024-8007

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …

Mitigation only
Fix from $1,950 2024-08-21
Build Of Apache Camel Hawtio HIGH 7.5
CVE-2024-7885

A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…

Mitigation only
Fix from $1,950 2024-08-21
Enterprise Linux HIGH 7.5
CVE-2024-44070

An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before t…

Fix: after 10.1
Fix from $1,950 2024-08-19
Openshift Ai HIGH 8.8
CVE-2024-7557

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. Whe…

Patch available
Fix from $1,950 2024-08-12
Enterprise Linux HIGH 7.5
CVE-2024-7006

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures thro…

Fix: after 4.6.0
Fix from $1,950 2024-08-12
Openstack Platform MEDIUM 5.0
CVE-2024-7319

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …

Mitigation only
Fix from $1,600 2024-08-02
Openshift Container Platform HIGH 7.7
CVE-2024-3056

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with…

Fix: after 5.2.0
Fix from $1,950 2024-08-02
Openshift Container Platform MEDIUM 6.5
CVE-2024-7079

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…

Mitigation only
Fix from $1,600 2024-07-24
Service Interconnect MEDIUM 5.3
CVE-2024-6535

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…

Mitigation only
Fix from $1,600 2024-07-17
Directory Server MEDIUM 6.5
CVE-2024-6237

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex…

Mitigation only
Fix from $1,600 2024-07-09
Enterprise Linux MEDIUM 6.8
CVE-2024-6505

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R…

Mitigation only
Fix from $1,600 2024-07-05
Enterprise Linux HIGH 7.5
CVE-2024-6239

A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed inp…

Fix: 24.06.0+
Fix from $1,950 2024-06-21
Enterprise Linux MEDIUM 6.7
CVE-2024-5742

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing…

Fix: 8.0+
Fix from $1,600 2024-06-12