Redhat
17,638 known vulnerabilities
Top Products
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit he
Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea
Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea
Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploi
Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass
Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrar
Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code v
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
JBoss KeyCloak: XSS in login-status-iframe.html
openstack-utils openstack-db has insecure password creation
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be grea
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used in
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any pa
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element canno
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
OpenShift cartridge allows remote URL retrieval
Katello has multiple XSS issues in various entities
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text whe
A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pres
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bou
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitr
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation o
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a l
SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c.
A password generation weakness exists in xquest through 2016-06-13.
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scr
A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames an
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string le
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with dee
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the managem
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration con
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature.
Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level
libuser has information disclosure when moving user's home directory
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started