Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati
A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE
A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client`
A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi
In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on
In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW
In the Linux kernel, the following vulnerability has been resolved: ice: fix double-free of tx_buf skb If ice_tso() or
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in icmpv6_rcv() Caching sad
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace
In the Linux kernel, the following vulnerability has been resolved: netfilter: nat: use kfree_rcu to release ops Flori
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv
A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing
A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a cra
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated
A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the
Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module
An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re
A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inheri
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding
A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of
The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules.
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce
A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke
A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taki
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block th
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started