Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-5142 A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (… Satellite 3.18.2 / 3.19.1+ Fix from $1,6002026-07-01 HIGH 8.8 CVE-2026-5136 A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This … Satellite 3.18.2 / 3.19.1+ Fix from $1,9502026-07-01 CRITICAL 9.1 CVE-2026-58016 A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malfo… Enterprise Linux 2.88.1+ Fix from $2,3002026-06-30 HIGH 8.6 CVE-2026-58014 A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key f… Enterprise Linux 2.88.1+ Fix from $1,9502026-06-30 HIGH 8.2 CVE-2026-58010 A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alig… Enterprise Linux 2.86.5+ Fix from $1,9502026-06-30 HIGH 8.2 CVE-2026-58012 A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change … Enterprise Linux 2.86.5+ Fix from $1,9502026-06-30 HIGH 8.2 CVE-2026-58013 A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator wit… Enterprise Linux 2.88.1+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-58011 A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an in… Enterprise Linux 2.86.5+ Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-58015 A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con… Enterprise Linux 2.88.1+ Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-4629 A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role … Build Of Keycloak No fix yet Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-12388 A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is … Build Of Keycloak Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.4 CVE-2026-12610 A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory … Enterprise Linux Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.2 CVE-2026-13757 A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_valu… Hardened Images after 4.22.1 Fix from $1,6002026-06-29 HIGH 8.8 CVE-2026-12856 A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Mark… Openshift Dev Spaces Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-13601 A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak applicati… Enterprise Linux 49.1+ Fix from $1,6002026-06-29 MEDIUM 5.1 CVE-2026-57965 A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This… Enterprise Linux Mitigation only Fix from $1,6002026-06-29 MEDIUM 5.3 CVE-2026-13595 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers … Hardened Images 2.42.2+ Fix from $1,6002026-06-29 MEDIUM 6.9 CVE-2026-13083 A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An at… Pen Drive 1.0.0-2+ Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-12993 A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE decla… Build Of Apicurio Registry after 3.2 Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-12975 A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing featu… Build Of Apicurio Registry after 3.2 Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-11800 A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an attacker with valid client cre… Build Of Keycloak 26.6.4+ Fix from $1,9502026-06-25 HIGH 7.4 CVE-2026-12992 A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.wsdl.importDocuments feature. W… Build Of Apicurio Registry after 3.2 Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-9800 A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, … Build Of Keycloak 26.4.13+ Fix from $1,9502026-06-25 HIGH 7.7 CVE-2026-9099 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticate… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 HIGH 7.3 CVE-2026-9086 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to clien… Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-9705 A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could … Build Of Keycloak 26.4.13 / 26.6.4+ Fix from $1,6002026-06-25 MEDIUM 6.2 CVE-2026-9073 A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication … Satellite Mitigation only Fix from $1,6002026-06-23 HIGH 7.8 CVE-2026-12112 A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad… Satellite Mitigation only Fix from $1,9502026-06-23 MEDIUM 6.5 CVE-2026-11820 A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod… Enterprise Linux Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.5 CVE-2026-11819 Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from … Enterprise Linux Mitigation only Fix from $1,6002026-06-23