Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-sty
3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user co
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker se
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a de
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. Thi
A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to
An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_pa
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a N
Two cross-site scripting vulnerabilities were fixed in Bodhi 5.6.1.
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 F
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when cal
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vu
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential m
Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project na
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive informatio
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call fu
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"),
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function o
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially cr
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, whil
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security poli
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbeh
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of ser
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packe
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's cho
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allow
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause o
An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to cras
A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. Thi
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. T
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started