Redhat
17,638 known vulnerabilities
Top Products
A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1.
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent
It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unp
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and J
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would rem
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to m
In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to th
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtua
A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivilege
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded serve
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary c
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privile
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with bac
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and o
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mel
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints s
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exp
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial o
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use th
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A speciall
A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple
A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function
A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict p
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST int
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypas
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way pa
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started