Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Virtio Win MEDIUM 5.5
CVE-2026-5164

A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap …

Patch available
Fix from $1,600 2026-03-30
Hardened Images HIGH 7.5
CVE-2026-5121

A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote at…

Patch available
Fix from $1,950 2026-03-30
Enterprise Linux HIGH 8.2
CVE-2026-5119

A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext …

No fix yet
Fix from $1,950 2026-03-30
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28369

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28367

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for…

Mitigation only
Fix from $2,300 2026-03-27
Build Of Apache Camel Hawtio CRITICAL 9.1
CVE-2026-28368

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed diffe…

Mitigation only
Fix from $2,300 2026-03-27
Enterprise Linux MEDIUM 5.5
CVE-2026-4948

A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, s…

Fix: after 2.4.0
Fix from $1,600 2026-03-27
Openshift Ai HIGH 8.1
CVE-2025-12805

A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to Llama Stack services deployed…

No fix yet
Fix from $1,950 2026-03-26
Hardened Images HIGH 7.5
CVE-2026-2100

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific I…

Patch available
Fix from $1,950 2026-03-26
Enterprise Linux MEDIUM 6.5
CVE-2026-2239

A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing a specially crafted PSD (Phot…

No fix yet
Fix from $1,600 2026-03-26
Enterprise Linux MEDIUM 6.5
CVE-2026-2272

A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the `ico_read_info` and `ico_read…

No fix yet
Fix from $1,600 2026-03-26
Hardened Images HIGH 8.2
CVE-2026-0966

A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exp…

Fix: 0.11.4+
Fix from $1,950 2026-03-26
Hardened Images MEDIUM 6.3
CVE-2026-0964

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could…

Fix: 0.11.4+
Fix from $1,600 2026-03-26
Enterprise Linux MEDIUM 5.5
CVE-2026-0967

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that wh…

Fix: after 0.11.3
Fix from $1,600 2026-03-26
Enterprise Linux HIGH 8.2
CVE-2026-2436

A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup_server_disconnect()` functio…

No fix yet
Fix from $1,950 2026-03-26
Build Of Keycloak HIGH 7.2
CVE-2026-3121

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…

Mitigation only
Fix from $1,950 2026-03-26
Openshift Container Platform MEDIUM 5.5
CVE-2026-4897

A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` set…

Mitigation only
Fix from $1,600 2026-03-26
Hardened Images HIGH 7.8
CVE-2026-4775

A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the putcontig8bitYCbCr44tile func…

Mitigation only
Fix from $1,950 2026-03-24
Openshift Container Platform MEDIUM 6.1
CVE-2026-4647

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue o…

Mitigation only
Fix from $1,600 2026-03-23
Hardened Images HIGH 7.5
CVE-2026-4424

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of t…

Patch available
Fix from $1,950 2026-03-19
Hardened Images MEDIUM 6.5
CVE-2026-4426

A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a fiel…

Patch available
Fix from $1,600 2026-03-19
Build Of Keycloak MEDIUM 5.8
CVE-2026-4366

A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain cli…

Mitigation only
Fix from $1,600 2026-03-18
Build Of Keycloak MEDIUM 5.3
CVE-2026-2575

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compres…

Fix: 26.4.10+
Fix from $1,600 2026-03-18
Build Of Keycloak HIGH 8.1
CVE-2026-2603

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…

Mitigation only
Fix from $1,950 2026-03-18
Build Of Keycloak HIGH 7.7
CVE-2026-2092

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions wh…

Mitigation only
Fix from $1,950 2026-03-18
Enterprise Linux HIGH 7.5
CVE-2026-4271

A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs in the HTTP/2 server impleme…

No fix yet
Fix from $1,950 2026-03-17
Enterprise Linux MEDIUM 6.5
CVE-2026-3633

A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function, could inject arbitrary head…

No fix yet
Fix from $1,600 2026-03-17
Enterprise Linux MEDIUM 6.5
CVE-2026-3634

A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage Return Line Feed (CRLF) sequ…

No fix yet
Fix from $1,600 2026-03-17
Enterprise Linux MEDIUM 5.5
CVE-2026-3632

A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because libsoup does not properly val…

No fix yet
Fix from $1,600 2026-03-17
Openshift Container Platform HIGH 7.1
CVE-2026-3441

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an atta…

Mitigation only
Fix from $1,950 2026-03-16