Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-42271 KEVEPSS 83% LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints use… Openshift Ai 1.83.7 / 2.25.8+ Fix from $1,9502026-05-08 CRITICAL 9.8 CVE-2026-42010 A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL ch… Hardened Images Mitigation only Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-34000 A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()… Enterprise Linux Mitigation only Fix from $2,3002026-05-05 CRITICAL 9.1 CVE-2026-34002 A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An a… Enterprise Linux Mitigation only Fix from $2,3002026-05-05 HIGH 7.4 CVE-2026-3833 A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically fo… Hardened Images No fix yet Fix from $1,9502026-04-30 CRITICAL 9.1 CVE-2026-33845 A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reass… Openshift Container Platform Mitigation only Fix from $2,3002026-04-30 MEDIUM 5.4 CVE-2026-7500 When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the ve… Build Of Keycloak Mitigation only Fix from $1,6002026-04-30 MEDIUM 5.5 CVE-2026-7163 A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allow… Multicluster Engine For Kubernetes Mitigation only Fix from $1,6002026-04-30 HIGH 7.5 CVE-2026-6732 A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document … Hardened Images 2.15.3 / 4.1.1.30+ Fix from $1,9502026-04-23 MEDIUM 5.3 CVE-2026-2708 A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-… Enterprise Linux No fix yet Fix from $1,6002026-04-23 HIGH 8.8 CVE-2026-6859 A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a r… Instructlab Mitigation only Fix from $1,9502026-04-22 HIGH 7.1 CVE-2026-6855 A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_… Instructlab Mitigation only Fix from $1,9502026-04-22 HIGH 8.1 CVE-2026-6848 A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as token generation or robot acc… Quay Mitigation only Fix from $1,9502026-04-22 HIGH 7.8 CVE-2026-6846 A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form… Hardened Images after 2.46 Fix from $1,9502026-04-22 MEDIUM 5.5 CVE-2026-6844 A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by prov… Hardened Images Mitigation only Fix from $1,6002026-04-22 MEDIUM 5.0 CVE-2026-6845 A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS… Hardened Images Mitigation only Fix from $1,6002026-04-22 MEDIUM 5.5 CVE-2026-6843 A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a nam… Openshift Container Platform Mitigation only Fix from $1,6002026-04-22 HIGH 7.8 CVE-2026-6384 A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` function allows an attacker to wri… Enterprise Linux Mitigation only Fix from $1,9502026-04-15 HIGH 7.1 CVE-2026-40917 A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when processing specially crafted ICNS i… Enterprise Linux Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.5 CVE-2026-40918 A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of service (DoS). This occurs due … Enterprise Linux Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.5 CVE-2026-40919 A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited when a user opens a speciall… Enterprise Linux Mitigation only Fix from $1,6002026-04-15 HIGH 7.8 CVE-2026-40915 A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by providing a specially crafted… Enterprise Linux Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.5 CVE-2026-40916 A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a local user to cause a Denial of… Enterprise Linux Mitigation only Fix from $1,6002026-04-15 MEDIUM 5.5 CVE-2026-6245 A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PAM passkey responder fails to … Openshift Container Platform Mitigation only Fix from $1,6002026-04-15 HIGH 7.8 CVE-2026-1462 A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded durin… Openshift Ai 2.25.7+ Fix from $1,9502026-04-13 CRITICAL 9.9 CVE-2026-5483 A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows… Openshift Ai 2.16.4 / 2.25.4+ Fix from $2,3002026-04-10 HIGH 7.5 CVE-2026-1584 A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with… Hardened Images Mitigation only Fix from $1,9502026-04-09 HIGH 7.0 CVE-2026-4878 A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` func… Openshift Container Platform No fix yet Fix from $1,9502026-04-09 MEDIUM 5.5 CVE-2026-32591 A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy ca… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-32590 A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database u… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08