Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2026-18382
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an…
Cost Management Metrics Operator
No fix yet
MEDIUM 6.5
CVE-2026-18207
A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of …
Build Of Keycloak
No fix yet
MEDIUM 5.5
CVE-2026-18201
Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator w…
Build Of Keycloak
No fix yet
HIGH 7.8
CVE-2026-66758
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bi…
Enterprise Linux
No fix yet
HIGH 7.1
CVE-2026-66759
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data…
Enterprise Linux
No fix yet
MEDIUM 5.5
CVE-2026-66757
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image …
Enterprise Linux
No fix yet
MEDIUM 6.5
CVE-2026-17059
A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…
Build Of Keycloak
No fix yet
HIGH 8.8
CVE-2026-59851
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ…
Hardened Images
No fix yet
HIGH 7.5
CVE-2026-59849
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when …
Hardened Images
No fix yet
HIGH 7.5
CVE-2026-59850
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data …
Hardened Images
No fix yet
HIGH 7.5
CVE-2026-59847
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, al…
Hardened Images
No fix yet
MEDIUM 5.3
CVE-2026-59848
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing …
Hardened Images
No fix yet
MEDIUM 5.9
CVE-2026-59845
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then b…
Hardened Images
No fix yet
MEDIUM 6.5
CVE-2026-59843
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel write…
Hardened Images
No fix yet
MEDIUM 6.5
CVE-2026-59844
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP ser…
Hardened Images
No fix yet
MEDIUM 5.3
CVE-2026-59842
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copie…
Hardened Images
No fix yet
HIGH 7.3
CVE-2026-15370
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack…
Hardened Images
No fix yet
MEDIUM 6.5
CVE-2026-16104
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-16108
A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-16093
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authe…
Build Of Keycloak
No fix yet
MEDIUM 5.9
CVE-2026-16089
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not prop…
Build Of Keycloak
No fix yet
MEDIUM 5.5
CVE-2026-15943
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated a…
Build Of Keycloak
No fix yet
HIGH 8.1
CVE-2026-1609
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-15154
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (R…
Openshift Ai
Mitigation only
MEDIUM 5.3
CVE-2026-14940
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When
normalizing a Distinguished Name (DN) that contains a legacy-quoted…
Directory Server
Mitigation only
HIGH 7.8
CVE-2026-58384
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-59089
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color …
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2026-58380
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null termin…
Enterprise Linux
Mitigation only
MEDIUM 5.4
CVE-2026-14614
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue al…
Build Of Keycloak
26.4.14 / 26.6.5+
MEDIUM 6.5
CVE-2026-5135
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing…
Satellite
3.18.2 / 3.19.1+