Redhat
17,638 known vulnerabilities
Top Products
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validati
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterpris
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex
It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBo
frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the E
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 all
An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c
Pagure: XSS possible in file attachment endpoint
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensi
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a d
Cache Poisoning issue exists in DNS Response Rate Limiting.
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
gdm3 3.14.2 and possibly later has an information leak before screen lock
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 al
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, wh
The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbi
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The u
JBoss AeroGear has reflected XSS via the password field
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
CloudForms stores user passwords in recoverable format
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 m
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web scri
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
php-symfony2-Validator has loss of information during serialization
evince is missing a check on number of pages which can lead to a segmentation fault
An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary fi
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permiss
While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buf
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when f
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started