Redhat
17,638 known vulnerabilities
Top Products
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method cal
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can res
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marve
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allow
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x ver
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions p
PyXML: Hash table collisions CPU usage Denial of Service
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Designate does not enforce the DNS protocol limit concerning record set sizes
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in Clou
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of se
cumin: At installation postgresql database user created without password
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers t
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
tog-Pegasus has a package hash collision DoS vulnerability
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar
A memory leak in the nfp_flower_spawn_vnic_reprs() function in drivers/net/ethernet/netronome/nfp/flower/main.c in the L
A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c in the Linux k
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11
A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the
A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 all
A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows att
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bo
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File uploa
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R)
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x bef
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is re
Moodle before 2.2.2 has users' private files included in course backups
Moodle has a database activity export permission issue where the export function of the database activity module exports
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle at
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started