Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-47866
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put…
Ceph
after 19.2.3
HIGH 7.5
CVE-2025-9784
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, ref…
Build Of Apache Camel For Spring Boot
Patch available
MEDIUM 5.3
CVE-2025-8419
A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send s…
Keycloak
Mitigation only
MEDIUM 6.5
CVE-2025-7784
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use…
Build Of Keycloak
Mitigation only
MEDIUM 6.7
CVE-2025-7519
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This iss…
Openshift Container Platform
Patch available
HIGH 7.1
CVE-2025-7365
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (Id…
Keycloak
Patch available
HIGH 7.5
CVE-2025-7424
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion du…
Openshift Container Platform
Mitigation only
HIGH 8.2
CVE-2025-32990
A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads ce…
Openshift Container Platform
Mitigation only
HIGH 8.2
CVE-2025-32988
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternati…
Openshift Container Platform
3.8.10+
MEDIUM 5.3
CVE-2025-32989
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2025-5351
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys i…
Openshift Container Platform
0.11.2+
HIGH 8.8
CVE-2025-5372
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation…
Openshift Container Platform
0.11.2+
MEDIUM 5.5
CVE-2025-6017
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vuln…
Advanced Cluster Management For Kubernetes
2.10.7 / 2.11.4+
MEDIUM 5.3
CVE-2025-6920
A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf…
Ai Inference Server
Mitigation only
MEDIUM 5.5
CVE-2025-5731
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in …
Data Grid
Mitigation only
MEDIUM 5.4
CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an inc…
Openshift Container Platform
0.11.2+
HIGH 7.5
CVE-2025-6021
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. …
Jboss Core Services
No fix yet
MEDIUM 6.6
CVE-2025-5918
A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowi…
Openshift Container Platform
3.8.0+
MEDIUM 5.6
CVE-2025-5916
A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Arc…
Openshift Container Platform
3.8.0+
MEDIUM 5.0
CVE-2025-5917
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes …
Openshift Container Platform
3.8.0+
HIGH 7.8
CVE-2025-5914
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involv…
Openshift Container Platform
3.8.0+
MEDIUM 6.6
CVE-2025-5915
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potent…
Openshift Container Platform
3.8.0+
MEDIUM 6.5
CVE-2025-47711
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific reques…
Enterprise Linux
No fix yet
HIGH 7.3
CVE-2025-35036
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation me…
Hibernate Validator
6.2.0+
MEDIUM 5.4
CVE-2025-5198
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T…
Advanced Cluster Security
Patch available
MEDIUM 6.5
CVE-2025-4478
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue …
Enterprise Linux
3.16.0+
MEDIUM 6.5
CVE-2024-4982
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could disco…
Pagure
5.14.1+
HIGH 7.1
CVE-2024-4981
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentio…
Pagure
5.14.1+
MEDIUM 6.5
CVE-2025-4374
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are gran…
Quay
after 3.14.0
MEDIUM 5.4
CVE-2025-3910
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven…
Build Of Keycloak
26.0.11+