Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2021-20288
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…
Ceph Storage
14.2.21+
MEDIUM 6.5
CVE-2021-3482
A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada…
Enterprise Linux
after 0.27.3
MEDIUM 6.3
CVE-2021-3413
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az…
Satellite
2.2.0+
MEDIUM 5.5
CVE-2021-3447
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod…
Ansible
1.2.2 / 3.8.2+
MEDIUM 6.5
CVE-2021-20291
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is u…
Openshift Container Platform
1.28.1+
HIGH 7.0
CVE-2021-20271
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to instal…
Enterprise Linux
4.15.1.3 / 4.16.1.3+
MEDIUM 5.3
CVE-2021-20289
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception…
Resteasy
1.13.4+
MEDIUM 6.3
CVE-2021-20197
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When…
Enterprise Linux
after 2.35
MEDIUM 5.3
CVE-2020-35518
When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un…
389 Directory Server
1.4.3.19 / 1.4.4.13+
CRITICAL 9.8
CVE-2021-3466EPSS 9%
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac…
Enterprise Linux
Patch available
MEDIUM 5.5
CVE-2021-3443
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A sp…
Enterprise Linux
2.0.27+
MEDIUM 5.5
CVE-2021-3446
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the …
Enterprise Linux
0.8.2+
HIGH 7.8
CVE-2019-19354
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac…
Openshift Container Platform
4.4.3+
HIGH 7.0
CVE-2019-19352
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attac…
Openshift Container Platform
Mitigation only
HIGH 7.0
CVE-2019-19353
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacke…
Openshift Container Platform
No fix yet
HIGH 7.8
CVE-2019-19349
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat …
Openshift
No fix yet
HIGH 7.8
CVE-2019-19350
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an…
Openshift
No fix yet
MEDIUM 5.7
CVE-2021-3409
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pr…
Enterprise Linux
after 5.2.0
HIGH 7.5
CVE-2019-19343
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holdi…
Jboss Remoting
2.0.25 / 5.0.14+
HIGH 7.5
CVE-2021-20222
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …
Keycloak
13.0.0+
HIGH 7.5
CVE-2021-20270
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SM…
Openshift Container Platform
after 2.7.3
HIGH 7.2
CVE-2019-10200
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloa…
Openshift Container Platform
Patch available
MEDIUM 6.3
CVE-2019-10225
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the…
Openshift
Mitigation only
HIGH 7.5
CVE-2019-14852
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break…
3scale Api Management
Mitigation only
HIGH 7.5
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle speci…
Openshift Container Platform
1.0.8 / 2.6.9+
HIGH 8.8
CVE-2021-3344
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into t…
Openshift Builder
4.5.33 / 4.6.16+
MEDIUM 5.3
CVE-2019-3897
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. R…
Certification
Mitigation only
HIGH 7.4
CVE-2021-20218
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using …
Kubernetes Client
4.7.2 / 4.11.2+
HIGH 8.1
CVE-2021-20179
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …
Certificate System
10.5.0 / 10.8.0+
CRITICAL 9.8
CVE-2021-20231
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Enterprise Linux
3.7.1+