Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openstack MEDIUM 6.6
CVE-2020-14355

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Bot…

Patch available
Fix from $1,600 2020-10-07
Wildfly Openssl HIGH 7.5
CVE-2020-25644

A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to caus…

Fix: 1.1.3+
Fix from $1,950 2020-10-06
Libvirt MEDIUM 6.7
CVE-2020-25637

A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network inte…

Fix: 6.8.0+
Fix from $1,600 2020-10-06
Ansible MEDIUM 5.5
CVE-2020-25635

A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. File…

Mitigation only
Fix from $1,600 2020-10-05
Ansible HIGH 7.1
CVE-2020-25636

A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written d…

Mitigation only
Fix from $1,950 2020-10-05
Ceph Storage MEDIUM 6.1
CVE-2020-25626

A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails…

Fix: 3.12.0+
Fix from $1,600 2020-09-30
Pagure MEDIUM 6.1
CVE-2019-11556

Pagure before 5.6 allows XSS via the templates/blame.html blame view.

Fix: 5.6+
Fix from $1,600 2020-09-25
Wildfly Elytron HIGH 7.5
CVE-2020-10714

A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an …

Fix: 1.11.3+
Fix from $1,950 2020-09-23
Ansible Engine HIGH 7.1
CVE-2020-14365

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using …

Fix: after 3.7.2
Fix from $1,950 2020-09-23
Openshift Container Platform MEDIUM 5.3
CVE-2020-14370

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-…

Fix: 2.0.5+
Fix from $1,600 2020-09-23
Resteasy MEDIUM 5.3
CVE-2020-25633

A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensi…

Fix: 3.14.0+
Fix from $1,600 2020-09-18
Xerces MEDIUM 5.3
CVE-2020-14338

A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforce…

Fix: 2.12.0+
Fix from $1,600 2020-09-17
Jboss Fuse HIGH 7.5
CVE-2020-10718

A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context…

Fix: 13.0.0+
Fix from $1,950 2020-09-16
Keycloak MEDIUM 6.1
CVE-2020-10748

A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows a…

Fix: 7.4.1+
Fix from $1,600 2020-09-16
Keycloak HIGH 7.5
CVE-2020-10758

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak …

Fix: 11.0.1+
Fix from $1,950 2020-09-16
Wildfly Elytron HIGH 7.5
CVE-2020-1748

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed whe…

Fix: 1.6.8.final-redhat-00001+
Fix from $1,950 2020-09-16
Enterprise Linux HIGH 7.8
CVE-2020-14382

A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on e…

Patch available
Fix from $1,950 2020-09-16
Jboss Data Grid MEDIUM 5.3
CVE-2020-1710

The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

Mitigation only
Fix from $1,600 2020-09-16
Enterprise Linux MEDIUM 6.0
CVE-2020-10759

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur…

No fix yet
Fix from $1,600 2020-09-15
Enterprise Linux HIGH 7.3
CVE-2020-0570

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privil…

Fix: 5.9.10 / 5.12.7+
Fix from $1,950 2020-09-14
Ansible Engine MEDIUM 5.5
CVE-2020-14330

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o…

Fix: 2.9.12+
Fix from $1,600 2020-09-11
Ansible Engine MEDIUM 5.5
CVE-2020-14332

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat…

Fix: 2.8.14 / 2.9.12+
Fix from $1,600 2020-09-11
Jboss Enterprise Application Platform HIGH 7.5
CVE-2020-14384

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable t…

Fix: 7.5.31.final-redhat-3+
Fix from $1,950 2020-09-09
Enterprise Linux MEDIUM 5.5
CVE-2020-14373

A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a specially crafted PDF file to …

Patch available
Fix from $1,600 2020-09-03
Openstack MEDIUM 5.0
CVE-2020-14364EPSS 5%

An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB pa…

Fix: 5.2.0+
Fix from $1,600 2020-08-31
Librepo HIGH 8.0
CVE-2020-14352

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repo…

Fix: 1.12.1+
Fix from $1,950 2020-08-30
Ansible HIGH 7.3
CVE-2019-14904

A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name…

Fix: 2.7.15 / 2.8.7+
Fix from $1,950 2020-08-26
Ovirt Engine MEDIUM 5.3
CVE-2020-10775

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…

Fix: after 4.4
Fix from $1,600 2020-08-24
Cloudforms Management Engine CRITICAL 9.1
CVE-2020-14324

A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerabil…

Fix: 5.11.7.0+
Fix from $2,300 2020-08-11
Cloudforms Management Engine HIGH 7.1
CVE-2020-14296

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…

Mitigation only
Fix from $1,950 2020-08-11