Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-3442 A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker comp… Openshift Container Platform No fix yet Fix from $1,9502026-03-16 MEDIUM 6.4 CVE-2025-8766 A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c… Openshift Data Foundation Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2025-57849 A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable … Fuse Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-2376 A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov… Quay Patch available Fix from $1,6002026-03-12 HIGH 7.3 CVE-2026-3099 A flaw was found in Libsoup. The server-side digest authentication implementation in the SoupAuthDomainDigest class does not properly track issued no… Enterprise Linux No fix yet Fix from $1,9502026-03-12 HIGH 8.8 CVE-2026-3047 A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is configured as an Identity Provider … Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 HIGH 8.1 CVE-2026-3009 A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even… Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2025-12801 A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi… Openshift Container Platform Mitigation only Fix from $1,6002026-03-04 HIGH 8.8 CVE-2026-0980 A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with … Satellite after 0.12.1 Fix from $1,9502026-02-27 MEDIUM 6.7 CVE-2025-9909 A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the crea… Ansible Automation Platform 2.6+ Fix from $1,6002026-02-27 MEDIUM 6.7 CVE-2025-9908 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated use… Ansible Automation Platform 2.6+ Fix from $1,6002026-02-27 MEDIUM 6.7 CVE-2025-9907 A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensi… Ansible Automation Platform 2.6+ Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2025-9572 n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, … Satellite 3.16.2+ Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2026-3118 A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation… Developer Hub Mitigation only Fix from $1,6002026-02-25 MEDIUM 5.5 CVE-2026-26104 A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The… Enterprise Linux Mitigation only Fix from $1,6002026-02-25 HIGH 7.1 CVE-2026-26103 A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper aut… Enterprise Linux Mitigation only Fix from $1,9502026-02-25 MEDIUM 5.3 CVE-2026-2443 A flaw was identified in libsoup, a widely used HTTP library in GNOME-based systems. When processing specially crafted HTTP Range headers, the librar… Enterprise Linux Mitigation only Fix from $1,6002026-02-13 CRITICAL 9.8 CVE-2026-1709EPSS 5% A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication.… Enterprise Linux Mitigation only Fix from $2,3002026-02-06 MEDIUM 6.5 CVE-2026-1801 A flaw was found in libsoup, an HTTP client/server library. This HTTP Request Smuggling vulnerability arises from non-RFC-compliant parsing in the so… Enterprise Linux Mitigation only Fix from $1,6002026-02-03 HIGH 7.5 CVE-2026-1616 The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack… Open Security Issue Management 2025.9.0+ Fix from $1,9502026-01-29 MEDIUM 5.8 CVE-2026-1539 A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended destinations. When handling HTT… Enterprise Linux Mitigation only Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-1536 A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (Carriage Return Line Feed) seq… Enterprise Linux No fix yet Fix from $1,6002026-01-28 MEDIUM 5.3 CVE-2026-1467 A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injection, occurs when an HTTP pro… Enterprise Linux No fix yet Fix from $1,6002026-01-27 MEDIUM 5.9 CVE-2026-0990 A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an… Hardened Images 2.15.2 / 4.1.1.30+ Fix from $1,6002026-01-15 CRITICAL 9.6 CVE-2025-12543 A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to pr… Build Of Apache Camel 2.2.39 / 2.3.21+ Fix from $2,3002026-01-07 HIGH 7.5 CVE-2025-14874 A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursi… Advanced Cluster Management For Kubernetes 7.0.11+ Fix from $1,9502025-12-18 MEDIUM 6.5 CVE-2025-14512 A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib In… Openshift 2.86.3+ Fix from $1,6002025-12-11 CRITICAL 9.8 CVE-2025-14087 A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potenti… Enterprise Linux 2.86.3+ Fix from $2,3002025-12-10 MEDIUM 5.5 CVE-2025-14010 A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica… Community.general Patch available Fix from $1,6002025-12-04 HIGH 7.7 CVE-2025-13601 A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the … Codeready Linux Builder No fix yet Fix from $1,9502025-11-26