Redhat
17,638 known vulnerabilities
Top Products
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
In the Linux kernel before 5.0, a memory leak exists in sit_init_net() in net/ipv6/sit.c when register_netdev() fails to
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML int
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the unco
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca
CoreOS Tectonic 1.7.x and 1.8.x before 1.8.7-tectonic.2 deploys the Grafana web application using default credentials (a
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename cont
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Lin
There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hyp
A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce
In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce
drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a N
drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NU
drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, l
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events
An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The e
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly se
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory.
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not prop
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl
In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discov
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if
Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for a
A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local ac
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The a
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of s
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker se
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker op
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker c
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started