Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.8
CVE-2023-0664

A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows inst…

Fix: 8.0.0+
Fix from $1,950 2023-03-29
Keycloak Node.js Adapter MEDIUM 6.1
CVE-2022-2237

A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio…

Mitigation only
Fix from $1,600 2023-03-27
Enterprise Linux HIGH 7.1
CVE-2023-1380EPSS 17%

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel.…

Fix: 4.14.315 / 4.19.283+
Fix from $1,950 2023-03-27
Enterprise Linux MEDIUM 6.8
CVE-2023-0778

A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a syml…

Mitigation only
Fix from $1,600 2023-03-27
Openshift Assisted Installer MEDIUM 5.5
CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the…

Fix: 1.0.25.3+
Fix from $1,600 2023-03-24
Ceph Storage MEDIUM 6.5
CVE-2023-0056

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated r…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Software Collections HIGH 8.6
CVE-2022-4904

A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbit…

Fix: 1.19.0+
Fix from $1,950 2023-03-06
Ceph Storage MEDIUM 6.5
CVE-2022-3854

A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash…

Mitigation only
Fix from $1,600 2023-03-06
Codeready Linux Builder HIGH 8.8
CVE-2019-8720 KEV

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.…

Mitigation only
Fix from $1,950 2023-03-06
Openstack Platform MEDIUM 6.5
CVE-2022-3277

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr…

Fix: 18.6.0 / 19.5.0+
Fix from $1,600 2023-03-06
Openshift Container Platform HIGH 7.0
CVE-2023-27561

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an att…

Fix: 1.1.5+
Fix from $1,950 2023-03-03
Directory Server MEDIUM 5.5
CVE-2023-1055

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib…

Mitigation only
Fix from $1,600 2023-02-27
Build Of Quarkus HIGH 7.5
CVE-2022-4492

The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least…

Mitigation only
Fix from $1,950 2023-02-23
Build Of Quarkus MEDIUM 6.1
CVE-2023-0044

If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Info…

Fix: 2.13.7+
Fix from $1,600 2023-02-23
Resteasy MEDIUM 5.5
CVE-2023-0482

In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files …

Patch available
Fix from $1,600 2023-02-17
Enterprise Linux HIGH 7.4
CVE-2023-0361

A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the …

Patch available
Fix from $1,950 2023-02-15
Enterprise Linux HIGH 8.8
CVE-2022-4254

sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters

Patch available
Fix from $1,950 2023-02-01
Openshift MEDIUM 6.3
CVE-2023-0229

A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged …

Mitigation only
Fix from $1,600 2023-01-26
Openstack MEDIUM 5.9
CVE-2022-3100

A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

Mitigation only
Fix from $1,600 2023-01-18
Openshift MEDIUM 5.3
CVE-2023-0296

The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Ev…

Mitigation only
Fix from $1,600 2023-01-17
Ceph HIGH 7.8
CVE-2022-3650

A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump,…

No fix yet
Fix from $1,950 2023-01-17
Keycloak CRITICAL 9.1
CVE-2022-3782EPSS 6%

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…

Mitigation only
Fix from $2,300 2023-01-13
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2022-3841

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re…

Mitigation only
Fix from $1,950 2023-01-13
Wildfly Elytron HIGH 7.4
CVE-2022-3143

wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equ…

Mitigation only
Fix from $1,950 2023-01-13
Keycloak MEDIUM 6.5
CVE-2023-0105

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker …

Mitigation only
Fix from $1,600 2023-01-13
Enterprise Linux HIGH 7.5
CVE-2022-4743

A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to c…

Fix: 2.26.0+
Fix from $1,950 2023-01-12
Enterprise Linux HIGH 7.8
CVE-2022-3715

A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

Fix: 5.1.8+
Fix from $1,950 2023-01-05
Openshift Container Platform MEDIUM 5.9
CVE-2021-4294

A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. …

Patch available
Fix from $1,600 2022-12-28