Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2026-10533 A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernet… Openshift Container Platform Mitigation only Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-46579 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli… Openshift Container Platform Mitigation only Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-42965 A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQ… Openshift Container Platform Mitigation only Fix from $1,6002026-05-29 CRITICAL 9.8 CVE-2026-4408 A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check … Openshift Container Platform 4.21.0+ Fix from $2,3002026-05-28 MEDIUM 6.8 CVE-2026-9802 A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal t… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-9803 A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specia… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 7.3 CVE-2026-9795 A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-9796 A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulne… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 7.5 CVE-2026-9793 A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claim… Build Of Keycloak Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-9792 A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (cli… Build Of Keycloak No fix yet Fix from $1,6002026-05-28 MEDIUM 5.3 CVE-2026-9794 A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAM… Build Of Keycloak Mitigation only Fix from $1,6002026-05-28 HIGH 8.8 CVE-2026-9704 A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web… Build Of Keycloak Mitigation only Fix from $1,9502026-05-27 MEDIUM 6.5 CVE-2026-1933 A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, … Openshift Container Platform 4.2.2+ Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-2340 A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of… Openshift Container Platform Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.8 CVE-2026-3012 A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA c… Openshift Container Platform 4.21.0+ Fix from $1,6002026-05-27 HIGH 7.8 CVE-2026-48864 A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files du… Hardened Images No fix yet Fix from $1,9502026-05-26 CRITICAL 9.0 CVE-2026-4480EPSS 14% A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print… Openshift Container Platform 4.2.1+ Fix from $2,3002026-05-26 MEDIUM 6.5 CVE-2026-9149 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negat… Hardened Images after 0.7.36 Fix from $1,6002026-05-21 MEDIUM 6.5 CVE-2026-9150 A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially craf… Hardened Images after 0.7.36 Fix from $1,6002026-05-20 HIGH 8.1 CVE-2026-9087 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identit… Build Of Keycloak Mitigation only Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-9064 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of cont… Directory Server Mitigation only Fix from $1,9502026-05-20 HIGH 8.1 CVE-2026-7504 A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation … Build Of Keycloak 26.4.12+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-7307 A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SA… Build Of Keycloak 26.4.12+ Fix from $1,9502026-05-19 HIGH 7.5 CVE-2026-7507 A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating… Build Of Keycloak 26.4.12+ Fix from $1,9502026-05-19 HIGH 7.1 CVE-2026-7571 A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disab… Build Of Keycloak 26.4.12+ Fix from $1,9502026-05-19 MEDIUM 6.8 CVE-2026-4630 A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Ser… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 MEDIUM 6.8 CVE-2026-37982 A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-37979 A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidentia… Build Of Keycloak 26.4.12+ Fix from $1,6002026-05-19 MEDIUM 5.4 CVE-2026-8922 A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC)… Build Of Keycloak Mitigation only Fix from $1,6002026-05-19 HIGH 7.5 CVE-2026-42009 A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The com… Hardened Images Mitigation only Fix from $1,9502026-05-18