Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Build Of Keycloak MEDIUM 6.8
CVE-2026-4630

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 6.8
CVE-2026-37982

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 6.5
CVE-2026-37979

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia…

Fix: 26.4.12+
Fix from $1,600 2026-05-19
Build Of Keycloak MEDIUM 5.4
CVE-2026-8922

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC)…

Mitigation only
Fix from $1,600 2026-05-19
Hardened Images HIGH 7.5
CVE-2026-42009

A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The com…

Mitigation only
Fix from $1,950 2026-05-18
Openshift Ai HIGH 8.8
CVE-2026-42271 KEVEPSS 83%

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use…

Fix: 1.83.7 / 2.25.8+
Fix from $1,950 2026-05-08
Hardened Images CRITICAL 9.8
CVE-2026-42010

A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch…

Mitigation only
Fix from $2,300 2026-05-07
Enterprise Linux CRITICAL 9.1
CVE-2026-34000

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()…

Mitigation only
Fix from $2,300 2026-05-05
Enterprise Linux CRITICAL 9.1
CVE-2026-34002

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a…

Mitigation only
Fix from $2,300 2026-05-05
Hardened Images HIGH 7.4
CVE-2026-3833

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically fo…

No fix yet
Fix from $1,950 2026-04-30
Openshift Container Platform CRITICAL 9.1
CVE-2026-33845

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass…

Mitigation only
Fix from $2,300 2026-04-30
Build Of Keycloak MEDIUM 5.4
CVE-2026-7500

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the ve…

Mitigation only
Fix from $1,600 2026-04-30
Multicluster Engine For Kubernetes MEDIUM 5.5
CVE-2026-7163

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allow…

Mitigation only
Fix from $1,600 2026-04-30
Hardened Images HIGH 7.5
CVE-2026-6732

A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document …

Fix: 2.15.3 / 4.1.1.30+
Fix from $1,950 2026-04-23
Enterprise Linux MEDIUM 5.3
CVE-2026-2708

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-…

No fix yet
Fix from $1,600 2026-04-23
Instructlab HIGH 8.8
CVE-2026-6859

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a r…

Mitigation only
Fix from $1,950 2026-04-22
Instructlab HIGH 7.1
CVE-2026-6855

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…

Mitigation only
Fix from $1,950 2026-04-22
Quay HIGH 8.1
CVE-2026-6848

A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc…

Mitigation only
Fix from $1,950 2026-04-22
Hardened Images HIGH 7.8
CVE-2026-6846

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form…

Fix: after 2.46
Fix from $1,950 2026-04-22
Hardened Images MEDIUM 5.5
CVE-2026-6844

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov…

Mitigation only
Fix from $1,600 2026-04-22
Hardened Images MEDIUM 5.0
CVE-2026-6845

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS…

Mitigation only
Fix from $1,600 2026-04-22
Openshift Container Platform MEDIUM 5.5
CVE-2026-6843

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a nam…

Mitigation only
Fix from $1,600 2026-04-22
Enterprise Linux HIGH 7.8
CVE-2026-6384

A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to wri…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux HIGH 7.1
CVE-2026-40917

A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS i…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40918

A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due …

Mitigation only
Fix from $1,600 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40919

A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a speciall…

Mitigation only
Fix from $1,600 2026-04-15
Enterprise Linux HIGH 7.8
CVE-2026-40915

A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted…

Mitigation only
Fix from $1,950 2026-04-15
Enterprise Linux MEDIUM 5.5
CVE-2026-40916

A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of…

Mitigation only
Fix from $1,600 2026-04-15
Openshift Container Platform MEDIUM 5.5
CVE-2026-6245

A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to …

Mitigation only
Fix from $1,600 2026-04-15
Openshift Ai HIGH 7.8
CVE-2026-1462

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin…

Fix: 2.25.7+
Fix from $1,950 2026-04-13