Redhat
17,638 known vulnerabilities
Top Products
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/ja
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/ja
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS
A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eve
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-a
A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool o
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resourc
A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and te
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an incons
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported ve
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported vers
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versi
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affec
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt e
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAP
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root
It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-b
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large intege
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discover
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon '
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filenam
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execu
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation o
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.34
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75 allowed an attacker who con
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started