Redhat
17,638 known vulnerabilities
Top Products
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadR
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanl
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when pa
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a
A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SK
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, wher
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at crea
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical butt
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user
A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC su
A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This fla
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ fro
A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further wr
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the con
A Null pointer dereference problem was found in ida_free in lib/idr.c in the Linux Kernel. This issue may allow an attac
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local att
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() f
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memo
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This f
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may all
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the fron
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction cou
A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syn
A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kerne
A use-after-free flaw was found in the netfilter subsystem of the Linux kernel. If the catchall element is garbage-colle
A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virt
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password
A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTabl
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) bec
sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitati
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and
A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. This issue occurs when two threads execu
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client coul
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different sup
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credenti
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated at
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a mal
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that woul
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attack
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permission
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation.
A vulnerability was found in OpenImageIO, where a heap buffer overflow exists in the src/gif.imageio/gifinput.cpp file.
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to t
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started