Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple RedhatWebkitgtk+1 more15Enterprise Linux Enterprise Linux AusEnterprise Linux Els+12 moreJul 15, 2026 Jul 30, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content m...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformSep 1, 2026 Jul 28, 2025 N/A· v4 3.7 LOW· v3 N/A· v2 A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as...Show more |
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-adm...Show more |
1Redhat 2Enterprise Linux Openshift Container PlatformSep 1, 2026 Jul 14, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code...Show more |
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information. |
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data. |
A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile...Show more |
2Redhat Xmlsoft3Enterprise Linux LibxsltOpenshift Container PlatformSep 1, 2026 Jul 10, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to cras...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformSep 1, 2026 Jul 10, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the template parsing logic within the certtool utility. When it reads certain settings from a template file, it allows an attacker to cause an...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformSep 1, 2026 Jul 10, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious use...Show more |
2Gnu Redhat3Enterprise Linux GnutlsOpenshift Container PlatformSep 1, 2026 Jul 10, 2025 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is in...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformSep 1, 2026 Jul 4, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is fr...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformSep 1, 2026 Jul 4, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL use...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Jun 17, 2026 Jul 2, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed clus...Show more |
A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enforce API key validation. However, the POST /invocations endpoint failed...Show more |
6Canonical DebianOpensuse+3 more8Debian Linux Enterprise LinuxLeap+5 moreJun 17, 2026 Jun 30, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. |
2Infinispan Redhat4Data Grid InfinispanJboss Enterprise Application Platform+1 moreJun 17, 2026 Jun 26, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed in plaintext and included in a command string that may expose the data in an error message when a co...Show more |
2Libssh Redhat3Enterprise Linux LibsshOpenshift Container PlatformSep 8, 2026 Jun 24, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyo...Show more |
A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive...Show more |
2Redhat Xmlsoft4Enterprise Linux Jboss Core ServicesLibxml2+1 moreSep 1, 2026 Jun 16, 2025 N/A· v4 2.5 LOW· v3 N/A· v2 A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to...Show more |