Redhat
17,638 known vulnerabilities
Top Products
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, wh
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to si
V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neuter
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Andr
Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, wh
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for A
A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Andr
Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorr
Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correct
Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.
The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that ar
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are J
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are aff
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are aff
Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext i
Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authent
Session fixation vulnerability in pcsd in pcs before 0.9.157.
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the a
Cross-site scripting (XSS) vulnerability in the default exception handler in RESTEasy allows remote attackers to inject
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, all
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which ma
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physicall
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channe
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) fo
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers t
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary we
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstac
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands a
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the loca
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate at
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix
Snoopy allows remote attackers to execute arbitrary commands.
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists due
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node di
Frequently Asked Questions
How many CVEs affect Redhat?
Redhat has 17,638 CVE records in our database, including 1817 critical and 6954 high severity vulnerabilities. 43 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Redhat vulnerabilities?
Redhat has 1817 critical severity (CVSS 9.0+) and 6954 high severity (CVSS 7.0-8.9) vulnerabilities. 43 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Redhat vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Redhat products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Redhat Vulnerabilities
CyberStrike scans your infrastructure for Redhat vulnerabilities and provides real-time remediation guidance.
Get Started