Redhat
17,638 known vulnerabilities
Top Products
An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacke
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Se
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner
A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. T
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copi
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacke
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads
A flaw was found in the Red Hat 3scale API Management Platform, where member permissions for an API's admin portal were
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials thro
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network pack
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of
A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, le
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Appl
A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made i
A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash
A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malici
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closur
There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw
It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the na
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyon
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a spe
A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application se
There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouvea
A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a
A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buf
A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using A
A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet proces
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attac
A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, suc
A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /
A flaw was found in Ansible Tower in versions before 3.7.2. A Server Side Request Forgery flaw can be abused by supplyin
A Server-side request forgery (SSRF) flaw was found in Ansible Tower in versions before 3.6.5 and before 3.7.2. Function
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access netwo
A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length g
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower use
A missing authorization flaw was found in the libvirt API responsible for changing the QEMU agent response timeout. This
A flaw was found in Ansible Tower when running jobs. This flaw allows an attacker to access the stdout of the executed j
A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started