redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2025-23368 | Medium | 0.9% | 8.1 | A flaw was found in Wildfly Elytron integration. The component does not implemen… | |
| CVE-2026-35091 | Medium | 0.9% | 8.2 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wr… | |
| CVE-2026-1933 | Medium | 0.9% | 7.1 | A flaw was found in Samba’s handling of NTFS-style reparse points on shares conf… | |
| CVE-2024-7341 | Medium | 0.8% | 7.1 | A session fixation issue was discovered in the SAML adapters provided by Keycloa… | |
| CVE-2026-44495 | Medium | 0.8% | 7.0 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to… | |
| CVE-2026-15722 | Medium | 0.8% | 7.5 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). Th… | |
| CVE-2026-9064 | Medium | 0.8% | 7.5 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in … | |
| CVE-2026-33845 | Medium | 0.8% | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len… | |
| CVE-2023-3640 | Medium | 0.8% | 7.0 | A possible unauthorized memory access flaw was found in the Linux kernel's cpu_e… | |
| CVE-2026-7307 | Medium | 0.7% | 7.5 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a spec… | |
| CVE-2023-6546 | Medium | 0.7% | 7.0 | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. … | |
| CVE-2025-71319 | Medium | 0.7% | 7.5 | image-size through 2.0.2 contains a denial of service vulnerability that allows … | |
| CVE-2021-44733 | Medium | 0.7% | 7.0 | A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Lin… | |
| CVE-2000-0963 | Medium | 0.7% | 7.2 | Buffer overflow in ncurses library allows local users to execute arbitrary comma… | |
| CVE-2026-44172 | Medium | 0.7% | 9.1 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18… | |
| CVE-2026-28369 | Medium | 0.7% | 8.7 | A flaw was found in Undertow. When Undertow receives an HTTP request where the f… | |
| CVE-2026-9800 | Medium | 0.7% | 8.1 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any auth… | |
| CVE-2026-59090 | Medium | 0.6% | 8.4 | A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign… | |
| CVE-2026-0966 | Medium | 0.6% | 8.2 | A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a… | |
| CVE-2026-1609 | Medium | 0.6% | 8.1 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant … | |
| CVE-2026-13476 | Medium | 0.6% | 7.3 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticate… | |
| CVE-2026-58016 | Medium | 0.5% | 7.5 | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new… | |
| CVE-2023-4692 | Medium | 0.5% | 7.5 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This is… | |
| CVE-2026-11770 | Medium | 0.5% | 7.5 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can… | |
| CVE-2023-42753 | Medium | 0.5% | 7.0 | An array indexing vulnerability was found in the netfilter subsystem of the Linu… | |
| CVE-2026-41731 | Medium | 0.5% | 8.1 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type h… | |
| CVE-2022-1055 | Medium | 0.5% | 7.8 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a… | |
| CVE-2002-0062 | Medium | 0.5% | 7.2 | Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used i… | |
| CVE-2026-59087 | Medium | 0.5% | 7.8 | A flaw was found in the GIMP image manipulation program, specifically within its… | |
| CVE-2026-19654 | Medium | 0.5% | 7.5 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the op… | |
| CVE-2026-46579 | Medium | 0.4% | 7.4 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminat… | |
| CVE-2025-5914 | Medium | 0.4% | 7.8 | A vulnerability has been identified in the libarchive library, specifically with… | |
| CVE-2026-12975 | Medium | 0.4% | 8.5 | A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() metho… | |
| CVE-2023-6610 | Medium | 0.4% | 7.1 | An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/clie… | |
| CVE-2026-2603 | Medium | 0.4% | 8.1 | A flaw was found in Keycloak. A remote attacker could bypass security controls b… | |
| CVE-2026-58014 | Medium | 0.4% | 7.3 | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_lo… | |
| CVE-2026-32590 | Medium | 0.4% | 7.1 | A flaw was found in Red Hat Quay's handling of resumable container image layer u… | |
| CVE-2022-1353 | Medium | 0.4% | 7.1 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in … | |
| CVE-2026-53006 | Medium | 0.4% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipv6: fix p… | |
| CVE-2024-9675 | Medium | 0.4% | 7.8 | A vulnerability was found in Buildah. Cache mounts do not properly validate that… | |
| CVE-2022-0330 | Medium | 0.4% | 7.8 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driv… | |
| CVE-2021-3501 | Medium | 0.4% | 7.1 | A flaw was found in the Linux kernel in versions before 5.12. The value of inter… | |
| CVE-2026-53002 | Medium | 0.4% | 9.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … | |
| CVE-2026-15572 | Medium | 0.4% | 8.8 | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy… | |
| CVE-2026-59091 | Medium | 0.4% | 7.3 | A flaw was found in GIMP's file format plugins, including those for PSD and PAA … | |
| CVE-2026-12992 | Medium | 0.3% | 7.4 | A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j W… | |
| CVE-2026-73198 | Medium | 0.3% | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vu… | |
| CVE-2026-73197 | Medium | 0.3% | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this… | |
| CVE-2026-3009 | Medium | 0.3% | 8.1 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak a… | |
| CVE-2026-16102 | Medium | 0.3% | 8.1 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak,… |