Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2024-50311
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnera…
Openshift Container Platform
Mitigation only
MEDIUM 5.3
CVE-2024-50312
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retri…
Openshift Container Platform
Patch available
HIGH 7.3
CVE-2024-10234
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or…
Build Of Keycloak
Mitigation only
MEDIUM 5.3
CVE-2024-9683
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…
Quay
Mitigation only
MEDIUM 6.1
CVE-2024-10033
A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious us…
Ansible Automation Platform
Mitigation only
MEDIUM 6.5
CVE-2024-9676
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…
Openshift Container Platform
Patch available
MEDIUM 5.3
CVE-2024-9671
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invo…
3scale Api Management Platform
Mitigation only
MEDIUM 6.1
CVE-2024-8883
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…
Build Of Keycloak
Mitigation only
MEDIUM 5.5
CVE-2024-8354
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a U…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2023-6841
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP…
Keycloak
Mitigation only
HIGH 7.1
CVE-2024-7341
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time…
Keycloak
7.6.10 / 22.0.12+
MEDIUM 6.1
CVE-2024-7260
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…
Build Of Keycloak
24.0.7+
CRITICAL 9.8
CVE-2024-7012
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…
Satellite
Mitigation only
CRITICAL 9.8
CVE-2024-7923
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…
Satellite
Mitigation only
MEDIUM 6.5
CVE-2024-4629
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By ini…
Keycloak
7.6.10 / 22.012+
MEDIUM 5.9
CVE-2024-8285
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …
Kroxylicious
Mitigation only
MEDIUM 6.2
CVE-2024-8235
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms where all…
Libvirt
10.7.0+
HIGH 8.1
CVE-2024-8007
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …
Openstack Platform
Mitigation only
HIGH 7.5
CVE-2024-7885
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue…
Build Of Apache Camel Hawtio
Mitigation only
HIGH 7.5
CVE-2024-44070
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before t…
Enterprise Linux
after 10.1
HIGH 8.8
CVE-2024-7557
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. Whe…
Openshift Ai
Patch available
HIGH 7.5
CVE-2024-7006
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures thro…
Enterprise Linux
after 4.6.0
MEDIUM 5.0
CVE-2024-7319
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …
Openstack Platform
Mitigation only
HIGH 7.7
CVE-2024-3056
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with…
Openshift Container Platform
after 5.2.0
MEDIUM 6.5
CVE-2024-7079
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…
Openshift Container Platform
Mitigation only
MEDIUM 5.3
CVE-2024-6535
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…
Service Interconnect
Mitigation only
MEDIUM 6.5
CVE-2024-6237
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific ex…
Directory Server
Mitigation only
MEDIUM 6.8
CVE-2024-6505
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within R…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2024-6239
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed inp…
Enterprise Linux
24.06.0+
MEDIUM 6.7
CVE-2024-5742
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing…
Enterprise Linux
8.0+