Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openstack HIGH 8.8
CVE-2022-38065

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functio…

No fix yet
Fix from $1,950 2022-12-21
Enterprise Linux HIGH 7.1
CVE-2022-3775

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bi…

Fix: after 2.06
Fix from $1,950 2022-12-19
Openshift HIGH 7.4
CVE-2022-3259

Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

Mitigation only
Fix from $1,950 2022-12-09
Openshift HIGH 8.1
CVE-2022-3262

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw a…

Mitigation only
Fix from $1,950 2022-12-08
Build Of Quarkus CRITICAL 9.8
CVE-2022-4116EPSS 33%

A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to…

Fix: 2.13.5 / 2.14.2+
Fix from $2,300 2022-11-22
Enterprise Linux MEDIUM 5.1
CVE-2022-3500

A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the …

Fix: 6.5.1+
Fix from $1,600 2022-11-22
Enterprise Linux MEDIUM 5.5
CVE-2022-3821

An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time a…

Fix: after 251
Fix from $1,600 2022-11-08
Fedora Coreos MEDIUM 5.5
CVE-2022-3675

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the…

Fix: 37.20221031.1.0+
Fix from $1,600 2022-11-03
Ansible HIGH 7.5
CVE-2022-3697

A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2_instance module. This flaw a…

Fix: 2.0.0 / 2.10.0+
Fix from $1,950 2022-10-28
Ansible Automation Platform MEDIUM 5.5
CVE-2022-3644

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the…

No fix yet
Fix from $1,600 2022-10-25
Virtualization MEDIUM 6.5
CVE-2022-2805

A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attac…

Mitigation only
Fix from $1,600 2022-10-19
3scale Api Management HIGH 8.8
CVE-2022-1414

3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user could use this flaw to inject s…

Mitigation only
Fix from $1,950 2022-10-19
Openshift HIGH 7.5
CVE-2013-4253

The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root …

Patch available
Fix from $1,950 2022-10-19
Openshift MEDIUM 5.5
CVE-2013-4281

In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users…

Patch available
Fix from $1,600 2022-10-19
Decision Manager HIGH 8.8
CVE-2019-14841

A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to …

Mitigation only
Fix from $1,950 2022-10-17
Decision Manager HIGH 7.5
CVE-2019-14840

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

No fix yet
Fix from $1,950 2022-10-17
Directory Server MEDIUM 6.5
CVE-2022-2850

A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using…

Fix: after 2.4.1
Fix from $1,600 2022-10-14
Bodhi MEDIUM 6.1
CVE-2020-15855

Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.

Fix: 5.6.1+
Fix from $1,600 2022-10-07
Virtualization HIGH 8.6
CVE-2014-0144

QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/bu…

Patch available
Fix from $1,950 2022-09-29
Virtualization MEDIUM 5.5
CVE-2014-0148

Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to …

Patch available
Fix from $1,600 2022-09-29
Satellite MEDIUM 5.5
CVE-2015-1931

IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 b…

Fix: 5.0.16.13 / 6.0.16.7+
Fix from $1,600 2022-09-29
Ansible Automation Platform MEDIUM 6.1
CVE-2022-3205

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje…

Mitigation only
Fix from $1,600 2022-09-13
Wildfly HIGH 7.5
CVE-2022-1278

A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.

Fix: 27.0.0+
Fix from $1,950 2022-09-13
Openshift Container Platform HIGH 7.1
CVE-2022-2989

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data …

Patch available
Fix from $1,950 2022-09-13
Openshift Container Platform HIGH 7.1
CVE-2022-2990

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data…

Fix: 1.27.1+
Fix from $1,950 2022-09-13
Enterprise Linux HIGH 7.8
CVE-2022-25308

A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi app…

Fix: 1.0.12+
Fix from $1,950 2022-09-06
Enterprise Linux MEDIUM 5.5
CVE-2022-25309

A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Enterprise Linux MEDIUM 5.5
CVE-2022-25310

A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. Thi…

Fix: 1.0.12+
Fix from $1,600 2022-09-06
Openstack Platform HIGH 8.1
CVE-2022-23451

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo…

Fix: 14.0.0+
Fix from $1,950 2022-09-06
Advanced Cluster Security HIGH 8.8
CVE-2022-1902

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw …

Patch available
Fix from $1,950 2022-09-01