Redhat
17,638 known vulnerabilities
Top Products
Adobe Flash Player versions 32.0.0.192 and earlier, 32.0.0.192 and earlier, and 32.0.0.192 and earlier have an use after
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials throug
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certific
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude paramete
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Applicati
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from th
The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encr
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using
A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict
A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 af
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/
An issue was discovered in dlpar_parse_cc_property in arch/powerpc/platforms/pseries/dlpar.c in the Linux kernel through
The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execut
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Pla
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel modul
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `r
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an o
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command does
Adobe Flash Player versions 32.0.0.171 and earlier, 32.0.0.171 and earlier, and 32.0.0.171 and earlier have a use after
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A m
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-61
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET F
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as p
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block,
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to ob
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a Securi
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3
An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer funct
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunde
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). T
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while hand
Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for bro
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started