Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleRedhat11Debian Linux Enterprise Linux DesktopEnterprise Linux Server+8 moreMay 13, 2026 Apr 24, 2017 N/A· v4 3.1 LOW· v3 2.1 LOW· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit...Show more |
3Debian OracleRedhat12Debian Linux Enterprise Linux DesktopEnterprise Linux Server+9 moreMay 13, 2026 Apr 24, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit:...Show more |
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with net...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreMay 13, 2026 Apr 24, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulner...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Apr 24, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulner...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Apr 24, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable"...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Apr 24, 2017 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable"...Show more |
4Debian MariadbOracle+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 13, 2026 Apr 24, 2017 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulner...Show more |
1Redhat 1Cloudforms Management Engine May 13, 2026 Apr 21, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information. |
2Openstack Redhat2Manila OpenstackMay 13, 2026 Apr 21, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authenticated users to inject arbitrary web script or HTML via the Metadata field in the "Create Share" for...Show more |
3Clusterlabs FedoraprojectRedhat3Enterprise Linux FedoraPcsMay 13, 2026 Apr 21, 2017 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 Session fixation vulnerability in pcsd in pcs before 0.9.157. |
3Clusterlabs FedoraprojectRedhat3Enterprise Linux FedoraPcsMay 13, 2026 Apr 21, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149. |
1Redhat 2Jboss Bpm Suite Jboss Enterprise Brms PlatformMay 13, 2026 Apr 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page. |
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Redhat 1Enterprise Virtualization May 13, 2026 Apr 20, 2017 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, allows physically proximate attackers to bypass a webadmin session timeout restriction via vectors rela...Show more |
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to...Show more |
2Firewalld Redhat5Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+2 moreMay 13, 2026 Apr 19, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries...Show more |
4Apache NetappOracle+1 more79Api Gateway Application Testing SuiteAutovue Vuelink Integration+76 moreMay 13, 2026 Apr 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more |
1Redhat 1Quickstart Cloud Installer May 13, 2026 Apr 14, 2017 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display. |
3Canonical Nettle ProjectRedhat6Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+3 moreMay 13, 2026 Apr 14, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |