Redhat
17,638 known vulnerabilities
Top Products
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packet
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Contai
A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the
curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter cou
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checkin
NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header pars
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attacker
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash whi
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacke
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribu
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application cra
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check t
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generat
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successf
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to se
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote atta
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corr
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform d
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform d
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform d
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to lea
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as
Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a rem
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker
Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potential
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started