Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux MEDIUM 5.3
CVE-2026-12969

An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is call…

Fix: 2.93+
Fix from $1,600 2026-06-23
Cluster Logging Operator MEDIUM 6.8
CVE-2026-10609

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output d…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 6.1
CVE-2026-55655

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible…

Mitigation only
Fix from $1,600 2026-06-23
Hardened Images MEDIUM 6.5
CVE-2026-55653

A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path…

No fix yet
Fix from $1,600 2026-06-23
Openshift Container Platform MEDIUM 5.9
CVE-2026-12725

A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies contain…

Fix: 2.93+
Fix from $1,600 2026-06-22
Openshift Container Platform HIGH 8.8
CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a …

Fix: 4.22.1+
Fix from $1,950 2026-06-22
Openshift Container Platform HIGH 8.3
CVE-2026-54100

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows …

Fix: after 4.22.1
Fix from $1,950 2026-06-22
Directory Server MEDIUM 5.0
CVE-2026-11791

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information…

Mitigation only
Fix from $1,600 2026-06-18
Openshift Service Mesh HIGH 7.5
CVE-2026-47774

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulne…

Fix: 1.35.11 / 1.36.7+
Fix from $1,950 2026-06-17
Directory Server MEDIUM 5.4
CVE-2026-12528

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) strin…

Patch available
Fix from $1,600 2026-06-17
Enterprise Linux HIGH 8.1
CVE-2026-1767

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could…

No fix yet
Fix from $1,950 2026-06-16
Enterprise Linux MEDIUM 6.1
CVE-2026-1766

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This…

No fix yet
Fix from $1,600 2026-06-16
Enterprise Linux MEDIUM 5.6
CVE-2026-1764

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v…

No fix yet
Fix from $1,600 2026-06-16
Advanced Cluster Management For Kubernetes HIGH 7.7
CVE-2026-44495

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…

Fix: 2.13.9 / 4.10.3+
Fix from $1,950 2026-06-11
Discovery HIGH 7.5
CVE-2025-71319

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by suppl…

Fix: 1.4.2+
Fix from $1,950 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11789

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a craf…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server HIGH 7.5
CVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing…

Mitigation only
Fix from $1,950 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11786

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolon…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server MEDIUM 6.3
CVE-2026-11787

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a he…

Mitigation only
Fix from $1,600 2026-06-09
Directory Server MEDIUM 6.5
CVE-2026-11611

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated c…

Mitigation only
Fix from $1,600 2026-06-08
Enterprise Linux HIGH 7.8
CVE-2026-50264

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DR…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50258

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * Xkb…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50259

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256]…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50260

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those …

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50261

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a …

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux MEDIUM 5.5
CVE-2026-50262

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can re…

Fix: 21.1.23 / 24.1.12+
Fix from $1,600 2026-06-05
Enterprise Linux MEDIUM 5.5
CVE-2026-50263

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing …

Fix: 21.1.23 / 24.1.12+
Fix from $1,600 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50256

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum …

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Enterprise Linux HIGH 7.8
CVE-2026-50257

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger…

Fix: 21.1.23 / 24.1.12+
Fix from $1,950 2026-06-05
Openshift Container Platform HIGH 8.8
CVE-2026-1784

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on…

Mitigation only
Fix from $1,950 2026-06-02