Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Platform HIGH 7.1
CVE-2026-3442

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker comp…

No fix yet
Fix from $1,950 2026-03-16
Openshift Data Foundation MEDIUM 6.4
CVE-2025-8766

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-03-13
Fuse MEDIUM 6.4
CVE-2025-57849

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable …

Mitigation only
Fix from $1,600 2026-03-13
Quay MEDIUM 5.4
CVE-2026-2376

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov…

Patch available
Fix from $1,600 2026-03-12
Enterprise Linux HIGH 7.3
CVE-2026-3099

A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued no…

No fix yet
Fix from $1,950 2026-03-12
Build Of Keycloak HIGH 8.8
CVE-2026-3047

A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider …

Mitigation only
Fix from $1,950 2026-03-05
Build Of Keycloak HIGH 8.1
CVE-2026-3009

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…

Mitigation only
Fix from $1,950 2026-03-05
Openshift Container Platform MEDIUM 6.5
CVE-2025-12801

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi…

Mitigation only
Fix from $1,600 2026-03-04
Satellite HIGH 8.8
CVE-2026-0980

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with …

Fix: after 0.12.1
Fix from $1,950 2026-02-27
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9909

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the crea…

Fix: 2.6+
Fix from $1,600 2026-02-27
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9908

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated use…

Fix: 2.6+
Fix from $1,600 2026-02-27
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9907

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensi…

Fix: 2.6+
Fix from $1,600 2026-02-27
Satellite MEDIUM 6.5
CVE-2025-9572

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, …

Fix: 3.16.2+
Fix from $1,600 2026-02-27
Developer Hub MEDIUM 6.5
CVE-2026-3118

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux MEDIUM 5.5
CVE-2026-26104

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The…

Mitigation only
Fix from $1,600 2026-02-25
Enterprise Linux HIGH 7.1
CVE-2026-26103

A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut…

Mitigation only
Fix from $1,950 2026-02-25
Enterprise Linux MEDIUM 5.3
CVE-2026-2443

A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the librar…

Mitigation only
Fix from $1,600 2026-02-13
Enterprise Linux CRITICAL 9.8
CVE-2026-1709EPSS 5%

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.…

Mitigation only
Fix from $2,300 2026-02-06
Enterprise Linux MEDIUM 6.5
CVE-2026-1801

A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so…

Mitigation only
Fix from $1,600 2026-02-03
Open Security Issue Management HIGH 7.5
CVE-2026-1616

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack…

Fix: 2025.9.0+
Fix from $1,950 2026-01-29
Enterprise Linux MEDIUM 5.8
CVE-2026-1539

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT…

Mitigation only
Fix from $1,600 2026-01-28
Enterprise Linux MEDIUM 5.3
CVE-2026-1536

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq…

No fix yet
Fix from $1,600 2026-01-28
Enterprise Linux MEDIUM 5.3
CVE-2026-1467

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro…

No fix yet
Fix from $1,600 2026-01-27
Hardened Images MEDIUM 5.9
CVE-2026-0990

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an…

Fix: 2.15.2 / 4.1.1.30+
Fix from $1,600 2026-01-15
Build Of Apache Camel CRITICAL 9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr…

Fix: 2.2.39 / 2.3.21+
Fix from $2,300 2026-01-07
Advanced Cluster Management For Kubernetes HIGH 7.5
CVE-2025-14874

A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursi…

Fix: 7.0.11+
Fix from $1,950 2025-12-18
Openshift MEDIUM 6.5
CVE-2025-14512

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib In…

Fix: 2.86.3+
Fix from $1,600 2025-12-11
Enterprise Linux CRITICAL 9.8
CVE-2025-14087

A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti…

Fix: 2.86.3+
Fix from $2,300 2025-12-10
Community.general MEDIUM 5.5
CVE-2025-14010

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica…

Patch available
Fix from $1,600 2025-12-04
Codeready Linux Builder HIGH 7.7
CVE-2025-13601

A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the …

No fix yet
Fix from $1,950 2025-11-26