Redhat
17,638 known vulnerabilities
Top Products
A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Ha
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po
A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso
A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co
A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_
A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it
A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer
A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter
A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to
A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the
A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing
A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a
A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-
A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c
A malicious SCP server can send unexpected paths that could make the client application override local files outside of
A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup
A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to th
A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A re
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t
IBM Knowledge Catalog Standard Cartridge 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.1, 5.1.1, 5,1.2, 5.1.3, 5.2.0, 5.2.1 stores poten
A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the
An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files
A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login
A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect
A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val
A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs
A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage
A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function
A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read,
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started