Redhat
17,638 known vulnerabilities
Top Products
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, tha
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in th
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker att
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potential
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not prop
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>
A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tu
A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBos
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25. A local attacker could supply a s
An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue o
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to
IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application con
IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input valid
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on th
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to r
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way wh
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker
Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible T
Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious at
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypas
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled a
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 reques
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV r
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery a
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short pass
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in ca
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a sy
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw a
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials co
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SEL
A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRU
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This on
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where Sess
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction o
libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asser
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrec
A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occ
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started