Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-6478
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow wh…
Enterprise Linux Eus
21.1.10 / 23.2.3+
HIGH 7.8
CVE-2023-6377
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory…
Enterprise Linux Eus
21.1.10 / 23.2.3+
HIGH 7.8
CVE-2023-5764
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from templa…
Ansible
2.14.12 / 2.15.7+
HIGH 7.5
CVE-2023-5379
A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.4
CVE-2023-6710
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious user to add a script in the 'alias' parameter in the…
Enterprise Linux
Mitigation only
MEDIUM 6.1
CVE-2023-4958
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this…
Advanced Cluster Security
Patch available
CRITICAL 9.1
CVE-2023-6394
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operati…
Build Of Quarkus
3.6.0+
MEDIUM 5.3
CVE-2023-6393
A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial…
Build Of Quarkus
Mitigation only
MEDIUM 5.3
CVE-2023-5871
A flaw was found in libnbd, due to a malicious Network Block Device (NBD), a protocol for accessing Block Devices such as hard disks over a Network. …
Libnbd
1.18.2+
MEDIUM 6.5
CVE-2023-5189
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …
Ansible Automation Platform
No fix yet
MEDIUM 6.5
CVE-2023-4061
A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from…
Jboss Enterprise Application Platform
15.0.30+
MEDIUM 6.6
CVE-2023-40660
A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi…
Enterprise Linux
after 0.23.0
MEDIUM 6.4
CVE-2023-40661
Several memory vulnerabilities were identified within the OpenSC packages, particularly in the card enrollment process using pkcs15-init when a user …
Enterprise Linux
after 0.23.0
MEDIUM 5.5
CVE-2023-4910
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens…
3scale Api Management
Mitigation only
MEDIUM 6.5
CVE-2023-42669
A vulnerability was found in Samba's "rpcecho" development server, a non-Windows RPC server used to test Samba's DCE/RPC stack elements. This vulnera…
Storage
4.17.12 / 4.18.8+
HIGH 7.0
CVE-2023-5088
A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overw…
Enterprise Linux
8.2.0+
CRITICAL 9.8
CVE-2023-3961
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…
Storage
4.17.12 / 4.18.8+
HIGH 7.5
CVE-2023-46847EPSS 88%
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to he…
Enterprise Linux
Mitigation only
HIGH 7.5
CVE-2023-46848EPSS 10%
Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ft…
Enterprise Linux
6.4+
HIGH 7.5
CVE-2023-5824EPSS 5%
A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HT…
Enterprise Linux
6.4+
MEDIUM 5.3
CVE-2023-46846EPSS 6%
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling pas…
Enterprise Linux
6.4+
MEDIUM 5.5
CVE-2023-38473
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
Enterprise Linux
0.9+
MEDIUM 5.5
CVE-2023-38469
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
Enterprise Linux
0.9+
MEDIUM 5.5
CVE-2023-38470
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
Enterprise Linux
0.9+
MEDIUM 5.5
CVE-2023-38471
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
Enterprise Linux
0.9+
MEDIUM 5.5
CVE-2023-38472
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
Enterprise Linux
0.9+
MEDIUM 5.5
CVE-2023-3164
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw all…
Enterprise Linux
4.6.0+
HIGH 7.2
CVE-2023-5408
A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif…
Openshift Container Platform
Patch available
HIGH 7.8
CVE-2023-3972
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files an…
Insights Client
3.2.2+
HIGH 7.5
CVE-2023-5625
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2…
Openshift Container Platform For Arm64
Patch available