Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Satellite MEDIUM 6.5
CVE-2026-5142

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (…

Fix: 3.18.2 / 3.19.1+
Fix from $1,600 2026-07-01
Satellite HIGH 8.8
CVE-2026-5136

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This …

Fix: 3.18.2 / 3.19.1+
Fix from $1,950 2026-07-01
Enterprise Linux CRITICAL 9.1
CVE-2026-58016

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo…

Fix: 2.88.1+
Fix from $2,300 2026-06-30
Enterprise Linux HIGH 8.6
CVE-2026-58014

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key f…

Fix: 2.88.1+
Fix from $1,950 2026-06-30
Enterprise Linux HIGH 8.2
CVE-2026-58010

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alig…

Fix: 2.86.5+
Fix from $1,950 2026-06-30
Enterprise Linux HIGH 8.2
CVE-2026-58012

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change …

Fix: 2.86.5+
Fix from $1,950 2026-06-30
Enterprise Linux HIGH 8.2
CVE-2026-58013

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator wit…

Fix: 2.88.1+
Fix from $1,950 2026-06-30
Enterprise Linux HIGH 7.5
CVE-2026-58011

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an in…

Fix: 2.86.5+
Fix from $1,950 2026-06-30
Enterprise Linux HIGH 7.5
CVE-2026-58015

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con…

Fix: 2.88.1+
Fix from $1,950 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role …

No fix yet
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-12388

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is …

Mitigation only
Fix from $1,600 2026-06-30
Enterprise Linux MEDIUM 6.4
CVE-2026-12610

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory …

Mitigation only
Fix from $1,600 2026-06-30
Hardened Images MEDIUM 6.2
CVE-2026-13757

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_valu…

Fix: after 4.22.1
Fix from $1,600 2026-06-29
Openshift Dev Spaces HIGH 8.8
CVE-2026-12856

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Mark…

Mitigation only
Fix from $1,950 2026-06-29
Enterprise Linux MEDIUM 6.5
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak applicati…

Fix: 49.1+
Fix from $1,600 2026-06-29
Enterprise Linux MEDIUM 5.1
CVE-2026-57965

A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This…

Mitigation only
Fix from $1,600 2026-06-29
Hardened Images MEDIUM 5.3
CVE-2026-13595

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers …

Fix: 2.42.2+
Fix from $1,600 2026-06-29
Pen Drive MEDIUM 6.9
CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at…

Fix: 1.0.0-2+
Fix from $1,600 2026-06-26
Build Of Apicurio Registry MEDIUM 6.5
CVE-2026-12993

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE decla…

Fix: after 3.2
Fix from $1,600 2026-06-26
Build Of Apicurio Registry HIGH 8.5
CVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing featu…

Fix: after 3.2
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 8.1
CVE-2026-11800

A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client cre…

Fix: 26.6.4+
Fix from $1,950 2026-06-25
Build Of Apicurio Registry HIGH 7.4
CVE-2026-12992

A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W…

Fix: after 3.2
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 8.1
CVE-2026-9800

A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, …

Fix: 26.4.13+
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 7.7
CVE-2026-9099

A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Build Of Keycloak HIGH 7.3
CVE-2026-9086

A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien…

Fix: 26.4.13 / 26.6.4+
Fix from $1,950 2026-06-25
Build Of Keycloak MEDIUM 6.5
CVE-2026-9705

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could …

Fix: 26.4.13 / 26.6.4+
Fix from $1,600 2026-06-25
Satellite MEDIUM 6.2
CVE-2026-9073

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication …

Mitigation only
Fix from $1,600 2026-06-23
Satellite HIGH 7.8
CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad…

Mitigation only
Fix from $1,950 2026-06-23
Enterprise Linux MEDIUM 6.5
CVE-2026-11820

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 5.5
CVE-2026-11819

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from …

Mitigation only
Fix from $1,600 2026-06-23