Redhat
17,638 known vulnerabilities
Top Products
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Lo
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines cou
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to ke
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Se
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries
An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenti
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated datab
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send mal
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorit
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through
A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by
There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_AD
A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls io
Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service
In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untru
A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP p
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final
A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could us
A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping
A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanis
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in Roo
An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture a
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message betw
There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able t
IBM Resilient SOAR V38.0 could allow a local privileged attacker to obtain sensitive information due to improper or none
IBM Resilient SOAR V38.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt high
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the
A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where i
Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjace
A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is
A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container co
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started