Redhat
17,638 known vulnerabilities
Top Products
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut
A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana
A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The is
A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vecto
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN)
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken()
A flaw exists in the org.keycloak.broker.oidc package where the OIDC broker incorrectly synchronizes the email_verified
A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see informat
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t
A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call
A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism doe
A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfil
A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW`
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the gli
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali
A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b
A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur
A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Atta
A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v
A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extensio
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl.
A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to wri
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a sp
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, an
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re
A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun
A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es
A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d
A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena
A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a
A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati
A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started