Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Origin Aggregated Logging MEDIUM 5.9
CVE-2022-0552

A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 cont…

Patch available
Fix from $1,600 2022-04-11
Developer Tools HIGH 7.5
CVE-2022-27649

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E…

Patch available
Fix from $1,950 2022-04-04
Keycloak HIGH 7.1
CVE-2021-3461

A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Prin…

Patch available
Fix from $1,950 2022-04-01
Business Central HIGH 7.5
CVE-2019-14839

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercep…

Fix: after 7.48.0
Fix from $1,950 2022-04-01
Kubeclient HIGH 8.1
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco…

Fix: 4.9.3+
Fix from $1,950 2022-03-25
3scale HIGH 7.5
CVE-2021-3814

It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably b…

Fix: 2.11.0+
Fix from $1,950 2022-03-25
Enterprise Linux MEDIUM 6.5
CVE-2021-3941

In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma…

Patch available
Fix from $1,600 2022-03-25
Libvirt MEDIUM 6.5
CVE-2021-4147

A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash,…

Fix: 2.33.0+
Fix from $1,600 2022-03-25
Keycloak MEDIUM 6.1
CVE-2021-20323EPSS 37%

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

Fix: 17.0.0+
Fix from $1,600 2022-03-25
389 Directory Server MEDIUM 6.5
CVE-2022-0996

A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

No fix yet
Fix from $1,600 2022-03-23
Satellite HIGH 8.0
CVE-2021-3589

An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host…

Fix: 7.1.0+
Fix from $1,950 2022-03-23
Enterprise Linux HIGH 7.5
CVE-2022-0918EPSS 6%

A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a de…

Patch available
Fix from $1,950 2022-03-16
Ansible MEDIUM 5.5
CVE-2021-20180

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2022-03-16
Descision Manager HIGH 7.5
CVE-2022-0853

A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and l…

No fix yet
Fix from $1,950 2022-03-11
Enterprise Linux HIGH 7.5
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae…

Fix: 260+
Fix from $1,950 2022-03-10
Coreos Installer HIGH 7.8
CVE-2021-20319

An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image sign…

Fix: 0.10.1+
Fix from $1,950 2022-03-04
Enterprise Linux HIGH 7.8
CVE-2021-3575

A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use …

Fix: after 2.4.0
Fix from $1,950 2022-03-04
Clair CRITICAL 9.8
CVE-2021-3762

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…

Fix: 0.4.8 / 0.5.5+
Fix from $2,300 2022-03-03
Enterprise Linux MEDIUM 5.5
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Doc…

Fix: 1.16.8 / 1.17.2+
Fix from $1,600 2022-03-03
Ansible Automation Platform Early Access MEDIUM 5.5
CVE-2021-3620

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by defa…

Fix: 2.9.27+
Fix from $1,600 2022-03-03
Libvirt MEDIUM 6.5
CVE-2021-3667

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function w…

Fix: after 7.5.0
Fix from $1,600 2022-03-02
Libvirt MEDIUM 6.3
CVE-2021-3631

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil…

Fix: 7.5.0+
Fix from $1,600 2022-03-02
Enterprise Linux MEDIUM 6.1
CVE-2021-3623

A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of…

Fix: 0.6.5 / 0.7.8+
Fix from $1,600 2022-03-02
Openstack Platform MEDIUM 6.1
CVE-2021-3654EPSS 27%

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Fix: 21.2.3 / 22.2.3+
Fix from $1,600 2022-03-02
Openshift Container Platform HIGH 7.5
CVE-2022-0711EPSS 17%

A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted H…

Fix: 2.2.21 / 2.3.18+
Fix from $1,950 2022-03-02
Enterprise Linux HIGH 7.8
CVE-2021-26252

A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of s…

Patch available
Fix from $1,950 2022-02-24
Enterprise Linux MEDIUM 6.5
CVE-2021-3596

A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not c…

Fix: 7.0.10-31+
Fix from $1,600 2022-02-24
Enterprise Linux MEDIUM 6.4
CVE-2021-3700

A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c…

Fix: 0.11.0+
Fix from $1,600 2022-02-24
Enterprise Linux MEDIUM 5.5
CVE-2021-4115

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threa…

Patch available
Fix from $1,600 2022-02-21
Enterprise Linux MEDIUM 5.5
CVE-2022-23645

swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerab…

Fix: 0.5.3 / 0.6.2+
Fix from $1,600 2022-02-18