Vulnerability index

Browse CVEs

2,581 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-32589 A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can inter… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,9502026-04-08 MEDIUM 6.5 CVE-2026-2377 A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to … Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2025-14243 A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and ema… Mirror Registry For Red Hat Openshift Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57853 A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w… Web Terminal Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57854 A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c… Openshift Update Service Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-58713 A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein… Process Automation Manager Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.7 CVE-2025-57851 A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57847 A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea… Ansible Automation Platform after 2.6 Fix from $1,6002026-04-08 HIGH 7.0 CVE-2025-14821 A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and man… Hardened Images 0.12.0+ Fix from $1,9502026-04-07 MEDIUM 5.5 CVE-2026-5745 A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_te… Hardened Images Mitigation only Fix from $1,6002026-04-07 HIGH 8.2 CVE-2026-4740 A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern… Advanced Cluster Management For Kubernetes No fix yet Fix from $1,9502026-04-07 MEDIUM 5.5 CVE-2026-5704 A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fu… Hardened Images No fix yet Fix from $1,6002026-04-06 HIGH 7.1 CVE-2026-5673 A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Interleave) parser, specifically i… Enterprise Linux No fix yet Fix from $1,9502026-04-06 MEDIUM 5.3 CVE-2026-37977 A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-… Build Of Keycloak No fix yet Fix from $1,6002026-04-06 MEDIUM 5.3 CVE-2026-3184 A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the suppl… Hardened Images Mitigation only Fix from $1,6002026-04-03 MEDIUM 5.5 CVE-2026-2625 A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Hat Package Manager (RPM) file.… Hardened Images Mitigation only Fix from $1,6002026-04-03 HIGH 8.1 CVE-2026-4636 A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows … Build Of Keycloak No fix yet Fix from $1,9502026-04-02 HIGH 7.5 CVE-2026-4634 A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessiv… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 HIGH 7.4 CVE-2026-4282 A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 HIGH 7.3 CVE-2026-3872 A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect… Build Of Keycloak Mitigation only Fix from $1,9502026-04-02 MEDIUM 5.3 CVE-2026-4325 A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability al… Build Of Keycloak Mitigation only Fix from $1,6002026-04-02 HIGH 8.2 CVE-2026-35091 A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit toke… Openshift No fix yet Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-35092 A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacke… Openshift No fix yet Fix from $1,9502026-04-01 HIGH 7.5 CVE-2026-5201 A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loader due to improper validation … Enterprise Linux Mitigation only Fix from $1,9502026-03-31 HIGH 7.8 CVE-2026-5165 A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it fails to properly manage mem… Virtio Win Patch available Fix from $1,9502026-03-30 MEDIUM 5.5 CVE-2026-5164 A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provided by a user during an unmap … Virtio Win Patch available Fix from $1,6002026-03-30 HIGH 7.5 CVE-2026-5121 A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote at… Hardened Images Patch available Fix from $1,9502026-03-30 HIGH 8.2 CVE-2026-5119 A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies are transmitted in cleartext … Enterprise Linux No fix yet Fix from $1,9502026-03-30 CRITICAL 9.1 CVE-2026-28369 A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly proce… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27 CRITICAL 9.1 CVE-2026-28367 A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for… Build Of Apache Camel Hawtio Mitigation only Fix from $2,3002026-03-27