Redhat
17,638 known vulnerabilities
Top Products
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse
It was observed that while login into Business-central console, HTTP request discloses sensitive information like userna
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly n
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escala
A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the drive
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x -
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the a
A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allo
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access t
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx)
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using Use
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linu
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a coc
A flaw was found in the permissions of a log file created by kexec-tools. This flaw allows a local unprivileged user to
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote att
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation im
A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c,
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplyin
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user cre
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes
A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through inva
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default config
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePool
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal val
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in us
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started