Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Platform MEDIUM 5.0
CVE-2026-10533

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet…

Mitigation only
Fix from $1,600 2026-06-01
Openshift Container Platform HIGH 7.5
CVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…

Mitigation only
Fix from $1,950 2026-05-29
Openshift Container Platform MEDIUM 6.5
CVE-2026-42965

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ…

Mitigation only
Fix from $1,600 2026-05-29
Openshift Container Platform CRITICAL 9.8
CVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check …

Fix: 4.21.0+
Fix from $2,300 2026-05-28
Build Of Keycloak MEDIUM 6.8
CVE-2026-9802

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal t…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak MEDIUM 5.3
CVE-2026-9803

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specia…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 7.3
CVE-2026-9795

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo…

Mitigation only
Fix from $1,950 2026-05-28
Build Of Keycloak MEDIUM 6.5
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulne…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 7.5
CVE-2026-9793

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim…

Mitigation only
Fix from $1,950 2026-05-28
Build Of Keycloak MEDIUM 6.5
CVE-2026-9792

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (cli…

No fix yet
Fix from $1,600 2026-05-28
Build Of Keycloak MEDIUM 5.3
CVE-2026-9794

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAM…

Mitigation only
Fix from $1,600 2026-05-28
Build Of Keycloak HIGH 8.8
CVE-2026-9704

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web…

Mitigation only
Fix from $1,950 2026-05-27
Openshift Container Platform MEDIUM 6.5
CVE-2026-1933

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, …

Fix: 4.2.2+
Fix from $1,600 2026-05-27
Openshift Container Platform MEDIUM 6.5
CVE-2026-2340

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of…

Mitigation only
Fix from $1,600 2026-05-27
Openshift Container Platform MEDIUM 6.8
CVE-2026-3012

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA c…

Fix: 4.21.0+
Fix from $1,600 2026-05-27
Hardened Images HIGH 7.8
CVE-2026-48864

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files du…

No fix yet
Fix from $1,950 2026-05-26
Openshift Container Platform CRITICAL 9.0
CVE-2026-4480EPSS 14%

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print…

Fix: 4.2.1+
Fix from $2,300 2026-05-26
Hardened Images MEDIUM 6.5
CVE-2026-9149

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat…

Fix: after 0.7.36
Fix from $1,600 2026-05-21
Hardened Images MEDIUM 6.5
CVE-2026-9150

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially craf…

Fix: after 0.7.36
Fix from $1,600 2026-05-20
Build Of Keycloak HIGH 8.1
CVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit…

Mitigation only
Fix from $1,950 2026-05-20
Directory Server HIGH 7.5
CVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont…

Mitigation only
Fix from $1,950 2026-05-20
Build Of Keycloak HIGH 8.1
CVE-2026-7504

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation …

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Build Of Keycloak HIGH 7.5
CVE-2026-7307

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SA…

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Build Of Keycloak HIGH 7.5
CVE-2026-7507

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating…

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Build Of Keycloak HIGH 7.1
CVE-2026-7571

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disab…

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Build Of Keycloak MEDIUM 6.8
CVE-2026-4630

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 6.8
CVE-2026-37982

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 6.5
CVE-2026-37979

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 5.4
CVE-2026-8922

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC)…

Mitigation only
Fix from $1,600 2026-05-19
Hardened Images HIGH 7.5
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The com…

Mitigation only
Fix from $1,950 2026-05-18