Redhat
17,638 known vulnerabilities
Top Products
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a
A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati
A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injectio
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks pro
A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay.
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and oth
A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into t
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-con
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-ci
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. Thi
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allow
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privil
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious con
A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in
A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wh
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with larg
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed t
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occu
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Fin
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while se
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote
An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running bec
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without typ
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gai
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in
A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at res
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cde
The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invali
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user re
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identi
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy col
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in U
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version
A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started