Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2024-3183
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new…
Enterprise Linux
Mitigation only
MEDIUM 5.9
CVE-2024-3049
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC t…
Enterprise Linux
1.1+
HIGH 7.5
CVE-2024-5037
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check d…
Openshift Container Platform
Patch available
MEDIUM 6.2
CVE-2024-3716
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…
Satellite
Mitigation only
HIGH 8.8
CVE-2024-3622
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configurati…
Mirror Registry
Mitigation only
MEDIUM 6.5
CVE-2024-3623
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of th…
Mirror Registry
Mitigation only
MEDIUM 6.5
CVE-2024-1102
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for…
Jboss Enterprise Application Platform
2.2.1+
HIGH 8.8
CVE-2023-6787
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…
Build Of Keycloak
22.0.10 / 24.0.3+
HIGH 7.1
CVE-2023-3758
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authoriza…
Codeready Linux Builder
Patch available
HIGH 8.1
CVE-2024-1132
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali…
Build Of Keycloak
22.0.10 / 24.0.3+
MEDIUM 5.5
CVE-2024-3567
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the…
Enterprise Linux
8.2.3+
HIGH 7.8
CVE-2024-0406
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…
Advanced Cluster Security
4.0.0 / 4.18.4+
MEDIUM 5.5
CVE-2024-2496
A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host inter…
Libvirt
9.8.0+
HIGH 7.5
CVE-2024-2002
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, poten…
Enterprise Linux
0.9.2+
MEDIUM 5.3
CVE-2023-7250
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less tha…
Enterprise Linux
3.15+
MEDIUM 5.5
CVE-2023-6725
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were impr…
Openstack Platform
Mitigation only
MEDIUM 6.5
CVE-2024-1725
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated atta…
Openshift Container Platform
Mitigation only
MEDIUM 5.3
CVE-2024-1722
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
Keycloak
Mitigation only
MEDIUM 6.7
CVE-2023-6917
A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services …
Enterprise Linux
6.2.0+
HIGH 7.3
CVE-2024-1488
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti…
Codeready Linux Builder
Patch available
HIGH 7.5
CVE-2023-50387EPSS 100%
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU…
Enterprise Linux
Patch available
HIGH 7.5
CVE-2023-50868EPSS 82%
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of se…
Enterprise Linux
4.8.5 / 4.9.3+
CRITICAL 9.3
CVE-2024-1485
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…
Openshift
0.0.0-20240206+
MEDIUM 5.3
CVE-2024-1459
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP reques…
Undertow
Mitigation only
MEDIUM 5.5
CVE-2024-1062
A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
389 Directory Server
2.2.0+
HIGH 7.5
CVE-2023-6356
A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP packages whe…
Codeready Linux Builder Eus
Mitigation only
MEDIUM 5.5
CVE-2024-0690
An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information …
Ansible
2.14.4 / 2.15.9+
HIGH 7.5
CVE-2023-4503
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created …
Jboss Enterprise Application Platform
Mitigation only
HIGH 7.5
CVE-2023-50782
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA …
Ansible Automation Platform
42.0.0+
HIGH 7.5
CVE-2023-50781
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which ma…
Enterprise Linux
Mitigation only