Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2012-1094
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched…
Jboss Application Server
7.1.1+
HIGH 7.8
CVE-2020-1737
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t…
Ansible Engine
2.7.17 / 2.8.9+
HIGH 7.0
CVE-2020-1706
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…
Openshift Container Platform
Mitigation only
MEDIUM 6.5
CVE-2019-14886
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context…
Decision Manager
Mitigation only
HIGH 7.5
CVE-2020-8659
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.
Openshift Service Mesh
after 1.13.0
HIGH 7.5
CVE-2020-8661
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
Openshift Service Mesh
after 1.13.0
HIGH 7.4
CVE-2020-1734
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=…
Ansible Engine
after 3.3.4
CRITICAL 9.8
CVE-2020-1731
A flaw was found in all versions of the Keycloak operator, before version 8.0.2,(community only) where the operator generates a random admin password…
Keycloak Operator
8.0.2+
CRITICAL 9.8
CVE-2019-14892EPSS 6%
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…
Decision Manager
2.6.7.3 / 2.8.11.5+
HIGH 7.5
CVE-2015-5201
VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack…
Enterprise Virtualization
3.5.6 / 6-6.7-20151117.0+
CRITICAL 9.8
CVE-2014-4657
The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…
Ansible
1.5.4+
MEDIUM 5.5
CVE-2014-4658
The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtai…
Ansible
1.5.5+
MEDIUM 5.5
CVE-2014-4659
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti…
Ansible
1.5.5+
CRITICAL 9.8
CVE-2014-4678EPSS 5%
The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code vi…
Ansible
1.6.4+
MEDIUM 5.5
CVE-2014-4660
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user…
Ansible
1.5.5+
HIGH 7.5
CVE-2012-6685
Nokogiri before 1.5.4 is vulnerable to XXE attacks
Cloudforms Management Engine
1.5.4+
CRITICAL 9.8
CVE-2014-4966
Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which …
Ansible
1.6.7+
CRITICAL 9.8
CVE-2014-4967
Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansib…
Ansible
1.6.7+
CRITICAL 9.8
CVE-2014-8089
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …
Enterprise Linux
1.12.9 / 2.2.8+
CRITICAL 9.8
CVE-2020-1693
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …
Spacewalk
2.9+
HIGH 7.8
CVE-2020-1704
An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…
Openshift Service Mesh
1.0.8+
HIGH 8.8
CVE-2020-3757EPSS 10%
Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion …
Enterprise Linux Desktop
32.0.0.314 / 32.0.0.321+
HIGH 7.3
CVE-2020-8595
Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact…
Openshift Service Mesh
after 1.4.3
CRITICAL 9.8
CVE-2014-0234
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows re…
Openshift
2.1+
MEDIUM 5.9
CVE-2020-1726
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted …
Openshift Container Platform
Patch available
MEDIUM 6.0
CVE-2020-1711
An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming f…
Openstack
4.2.1+
HIGH 8.8
CVE-2013-4535
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm imag…
Virtualization
1.7.2+
MEDIUM 5.4
CVE-2020-1697
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated pro…
Keycloak
9.0.0+
HIGH 8.8
CVE-2012-4512EPSS 12%
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem…
Enterprise Linux
No fix yet
HIGH 7.0
CVE-2020-1708
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…
Openshift Container Platform
Mitigation only