Redhat
17,638 known vulnerabilities
Top Products
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, w
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which woul
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initial
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the tim
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured co
A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corne
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vuln
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual rem
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packag
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models w
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me
A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permission
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a cra
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuou
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server cras
A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protecti
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the ind
IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted s
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. B
NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not
NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of excepti
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer der
NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A succes
NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful
NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged op
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute pri
A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth tok
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This
A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), i
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to byp
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le
IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read
A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in p
A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text for
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentica
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started