Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifi
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronizatio
A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabl
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vul
An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does n
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtu
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecti
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can w
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sani
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post log
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, w
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulne
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly san
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification v
A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from t
A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not
A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an i
A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.
qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, whic
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, wi
A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to t
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization chec
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-v
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified.
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a n
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prio
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly co
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leadi
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argum
A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a play
The implementations of PKCS#1 v1.5 key transport mechanism for XMLEncryption in JBossWS and Apache WSS4J before 1.6.5 is
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-c
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function f
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3,
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are sto
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started