Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched
A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension
A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifical
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i
When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitra
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` funct
A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited
A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se
A flaw was found in GIMP. This vulnerability, a heap buffer over-read in the `icns_slurp()` function, occurs when proces
A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo
A flaw was found in GIMP. A remote attacker could exploit an integer overflow vulnerability in the FITS image loader by
A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA
A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S
A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Ha
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition
A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u
A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm
A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit
A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum
A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems f
A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from
A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd fi
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems f
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from th
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secur
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically w
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM).
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to
A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Inter
A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vuln
A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h`
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started