Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2011-3606
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…
Jboss Application Server
Mitigation only
MEDIUM 6.5
CVE-2019-10217
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP m…
Ansible
2.8.4+
MEDIUM 6.5
CVE-2019-10213
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t…
Openshift Container Platform
Patch available
HIGH 7.1
CVE-2019-14822
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another…
Enterprise Linux
1.5.22+
MEDIUM 5.9
CVE-2019-10214
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Con…
Openshift Container Platform
Patch available
HIGH 8.8
CVE-2019-10174
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to in…
Fuse
8.2.12 / 9.4.17+
MEDIUM 6.5
CVE-2015-5694
Designate does not enforce the DNS protocol limit concerning record set sizes
Enterprise Linux Openstack Platform
Mitigation only
CRITICAL 9.8
CVE-2014-3585
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
Redhat Upgrade Tool
Mitigation only
MEDIUM 6.5
CVE-2015-1780
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
Ovirt Engine
Mitigation only
MEDIUM 6.5
CVE-2019-10206
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by …
Ansible
2.6.19 / 2.7.13+
MEDIUM 5.4
CVE-2018-10854
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…
Cloudforms Management Engine
Mitigation only
CRITICAL 9.8
CVE-2014-3700
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Edeploy
after 1.6.0
CRITICAL 9.8
CVE-2012-3460
cumin: At installation postgresql database user created without password
Enterprise Mrg
Mitigation only
MEDIUM 5.5
CVE-2014-0084
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.…
Openshift Origin
2014-02-14+
MEDIUM 5.5
CVE-2012-6136
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
Tuned
Mitigation only
HIGH 7.5
CVE-2011-4967
tog-Pegasus has a package hash collision DoS vulnerability
Enterprise Linux
2.12+
MEDIUM 5.5
CVE-2014-5118
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Enterprise Linux
1.8.2+
HIGH 7.5
CVE-2019-10172EPSS 17%
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c…
Jboss Enterprise Application Platform
after 1.9.13
HIGH 7.8
CVE-2014-0023
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
Openshift
Mitigation only
HIGH 7.8
CVE-2019-0155
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;…
Enterprise Linux Server Aus
4.4.201 / 4.9.201+
HIGH 7.5
CVE-2019-14818
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious…
Enterprise Linux Fast Datapath
16.11.10 / 17.11.8+
MEDIUM 5.9
CVE-2014-8167
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
Enterprise Virtualization
Mitigation only
MEDIUM 6.1
CVE-2014-3592
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
Openshift Origin
after 2014-08-13
MEDIUM 6.1
CVE-2010-3857
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
Jboss Business Rules Management System
5.1.0+
MEDIUM 6.5
CVE-2014-3599
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
Hornetq
after 2.4.5
CRITICAL 9.8
CVE-2011-2897
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw
Enterprise Linux
after 2.31.1
HIGH 7.5
CVE-2019-10222
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph…
Ceph Storage
Patch available
MEDIUM 6.5
CVE-2019-14824
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…
Enterprise Linux
Mitigation only
MEDIUM 6.5
CVE-2019-14860
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of prote…
Fuse
7.5.0+
MEDIUM 6.1
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially mal…
Hibernate Validator
6.0.18+