Redhat
redhat
5,653 CVEs • 533 products
Products (533)
Click to collapseToggle
Products (533)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Almalinux ArchlinuxGentoo+5 more9Almalinux Arch LinuxEnterprise Linux+6 moreMay 26, 2026 Jan 14, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, t...Show more |
8Almalinux ArchlinuxGentoo+5 more22Almalinux Arch LinuxEnterprise Linux+19 moreApr 14, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...Show more |
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttNov 14, 2024 Nov 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info. |
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttNov 14, 2024 Nov 12, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original sender. |
3Mutt NeomuttRedhat3Enterprise Linux MuttNeomuttJul 16, 2025 Nov 12, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of the recipients to compr...Show more |
2Hibernate Redhat5Codeready Studio Hibernate ValidatorJboss Enterprise Application Platform+2 moreJun 24, 2025 Nov 7, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than characte...Show more |
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information. |
2Linux Redhat2Enterprise Linux Linux KernelNov 3, 2025 Oct 29, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced sprintf() calls blindly with snprintf()....Show more |
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing special characters bypass...Show more |
1Redhat 1Openshift Container Platform Jan 15, 2025 Oct 22, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure t...Show more |
1Redhat 1Openshift Container Platform Feb 25, 2025 Oct 22, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request...Show more |
1Redhat 2Build Of Keycloak Jboss Enterprise Application PlatformJul 23, 2025 Oct 22, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could...Show more |
A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the authentication mechanism, reducing the overall security of password enfo...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideMar 26, 2025 Oct 16, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL,...Show more |
1Redhat 15Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+12 moreMar 19, 2026 Oct 15, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill whe...Show more |
2Buildah Project Redhat14Buildah Enterprise LinuxEnterprise Linux Eus+11 moreAug 25, 2025 Oct 9, 2024 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary d...Show more |
1Redhat 13scale Api Management Platform Dec 4, 2024 Oct 9, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. Anyone can see the invoice if the URL is known or guessed. |
2Containers Redhat3Common Enterprise LinuxOpenshift Container PlatformDec 11, 2024 Oct 1, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to...Show more |
1Redhat 6Build Of Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Z+3 moreNov 26, 2024 Sep 19, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive informati...Show more |
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivileged guest user to c...Show more |