Redhat
17,638 known vulnerabilities
Top Products
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. I
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only
It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying i
A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repo
The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on ev
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to auth
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not prope
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowled
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces
WildFly Core before version 6.0.0.Alpha3 does not properly validate file paths in .war archives, allowing for the extrac
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could b
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks du
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when us
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE fla
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of se
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when ce
A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the prev
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special str
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocompl
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" a
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration
An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14,
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of cli
It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cook
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection
CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the ra
An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly c
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pk
In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-mi
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped i
plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a
Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a cra
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms.
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with mul
Adobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation cou
Adobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could le
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started