Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Ai CRITICAL 9.9
CVE-2026-5483

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…

Fix: 2.16.4 / 2.25.4+
Fix from $2,300 2026-04-10
Hardened Images HIGH 7.5
CVE-2026-1584

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with…

Mitigation only
Fix from $1,950 2026-04-09
Openshift Container Platform HIGH 7.0
CVE-2026-4878

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` func…

No fix yet
Fix from $1,950 2026-04-09
Mirror Registry For Red Hat Openshift MEDIUM 5.5
CVE-2026-32591

A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca…

Mitigation only
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 8.8
CVE-2026-32590

A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u…

Mitigation only
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift HIGH 7.4
CVE-2026-32589

A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter…

Mitigation only
Fix from $1,950 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 6.5
CVE-2026-2377

A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to …

Mitigation only
Fix from $1,600 2026-04-08
Mirror Registry For Red Hat Openshift MEDIUM 5.3
CVE-2025-14243

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and ema…

Mitigation only
Fix from $1,600 2026-04-08
Web Terminal MEDIUM 6.4
CVE-2025-57853

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w…

Mitigation only
Fix from $1,600 2026-04-08
Openshift Update Service MEDIUM 6.4
CVE-2025-57854

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-04-08
Process Automation Manager MEDIUM 6.4
CVE-2025-58713

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Advanced Cluster Management For Kubernetes MEDIUM 6.7
CVE-2025-57851

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Ansible Automation Platform MEDIUM 6.4
CVE-2025-57847

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea…

Fix: after 2.6
Fix from $1,600 2026-04-08
Hardened Images HIGH 7.0
CVE-2025-14821

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and man…

Fix: 0.12.0+
Fix from $1,950 2026-04-07
Hardened Images MEDIUM 5.5
CVE-2026-5745

A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_te…

Mitigation only
Fix from $1,600 2026-04-07
Advanced Cluster Management For Kubernetes HIGH 8.2
CVE-2026-4740

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern…

No fix yet
Fix from $1,950 2026-04-07
Hardened Images MEDIUM 5.5
CVE-2026-5704

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu…

No fix yet
Fix from $1,600 2026-04-06
Enterprise Linux HIGH 7.1
CVE-2026-5673

A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically i…

No fix yet
Fix from $1,950 2026-04-06
Build Of Keycloak MEDIUM 5.3
CVE-2026-37977

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-…

No fix yet
Fix from $1,600 2026-04-06
Hardened Images MEDIUM 5.3
CVE-2026-3184

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the suppl…

Mitigation only
Fix from $1,600 2026-04-03
Hardened Images MEDIUM 5.5
CVE-2026-2625

A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.…

Mitigation only
Fix from $1,600 2026-04-03
Build Of Keycloak HIGH 8.1
CVE-2026-4636

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows …

No fix yet
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.5
CVE-2026-4634

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessiv…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.4
CVE-2026-4282

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak HIGH 7.3
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…

Mitigation only
Fix from $1,950 2026-04-02
Build Of Keycloak MEDIUM 5.3
CVE-2026-4325

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al…

Mitigation only
Fix from $1,600 2026-04-02
Openshift HIGH 8.2
CVE-2026-35091

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit toke…

No fix yet
Fix from $1,950 2026-04-01
Openshift HIGH 7.5
CVE-2026-35092

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacke…

No fix yet
Fix from $1,950 2026-04-01
Enterprise Linux HIGH 7.5
CVE-2026-5201

A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation …

Mitigation only
Fix from $1,950 2026-03-31
Virtio Win HIGH 7.8
CVE-2026-5165

A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage mem…

Patch available
Fix from $1,950 2026-03-30