redhat
353 known vulnerabilities affecting redhat products.
Products
enterprise_linux 215
openshift_container_platform 86
build_of_keycloak 64
hardened_images 48
enterprise_linux_eus 16
enterprise_linux_server 15
jboss_enterprise_application_platform 15
single_sign-on 15
quay 14
enterprise_linux_server_aus 14
enterprise_linux_for_power_little_endian 13
enterprise_linux_for_ibm_z_systems 13
enterprise_linux_workstation 13
enterprise_linux_server_tus 12
389_directory_server 12
directory_server 11
enterprise_linux_for_ibm_z_systems_eus 11
enterprise_linux_desktop 11
enterprise_linux_for_power_little_endian_eus 11
jboss_enterprise_application_platform_expansion_pack 11
enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 9
data_grid 9
openshift_update_service 8
jboss_core_services 7
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2026-31431 | Act now | 99.9% | 7.8 | ● | In the Linux kernel, the following vulnerability has been resolved: crypto: alg… |
| CVE-2017-12615 | Act now | 99.6% | 8.1 | ● | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.… |
| CVE-2026-34486 | Act now | 98.6% | 7.5 | ● | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f… |
| CVE-2012-4681 | Act now | 98.5% | 9.8 | ● | Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Orac… |
| CVE-2021-4034 | Act now | 94.9% | 7.8 | ● | A local privilege escalation vulnerability was found on polkit's pkexec utility.… |
| CVE-2016-4117 | Act now | 94.4% | 9.8 | ● | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arb… |
| CVE-2012-1723 | Act now | 93.7% | 9.8 | ● | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Ora… |
| CVE-2017-12149 | Act now | 90.7% | 9.8 | ● | In Jboss Application Server as shipped with Red Hat Enterprise Application Platf… |
| CVE-2016-8735 | Act now | 90.3% | 9.8 | ● | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7… |
| CVE-2018-15982 | Act now | 89.1% | 7.8 | ● | Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a … |
| CVE-2010-0738 | Act now | 79.4% | 5.3 | ● | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Applicati… |
| CVE-2010-1428 | Act now | 62.1% | 7.5 | ● | The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Applica… |
| CVE-2026-48710 | Act now | 36.3% | 6.5 | ● | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the H… |
| CVE-2024-1086 | Act now | 28.1% | 7.8 | ● | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon… |
| CVE-2015-3246 | Act now | 8.8% | 5.1 | ● | libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper progr… |
| CVE-2015-5287 | Act now | 5.0% | 7.8 | ● | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.… |
| CVE-2023-46847 | High | 88.4% | 8.6 | Squid is vulnerable to a Denial of Service, where a remote attacker can perform… | |
| CVE-2019-10086 | Medium | 29.2% | 7.3 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh… | |
| CVE-2026-21710 | Medium | 25.0% | 7.5 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a re… | |
| CVE-2023-1380 | Medium | 16.5% | 7.1 | A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net… | |
| CVE-2026-4480 | Medium | 13.9% | 9.0 | A flaw was found in the Samba printing subsystem. Samba passes the client-contro… | |
| CVE-2026-9256 | Medium | 10.9% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo… | |
| CVE-2024-12085 | Medium | 8.8% | 7.5 | A flaw was found in rsync which could be triggered when rsync compares file chec… | |
| CVE-2026-42055 | Medium | 6.5% | 8.1 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_m… | |
| CVE-2022-27666 | Medium | 5.5% | 7.8 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ip… | |
| CVE-2024-1635 | Medium | 4.6% | 7.5 | A vulnerability was found in Undertow. This vulnerability impacts a server that … | |
| CVE-2015-1862 | Medium | 3.0% | 7.0 | The crash reporting feature in Abrt allows local users to gain privileges by lev… | |
| CVE-2024-7885 | Medium | 2.6% | 7.5 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses… | |
| CVE-2026-4408 | Medium | 2.5% | 9.0 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S… | |
| CVE-2025-9784 | Medium | 2.3% | 7.5 | A flaw was found in Undertow where malformed client requests can trigger server-… | |
| CVE-2022-1199 | Medium | 2.0% | 7.5 | A flaw was found in the Linux kernel. This flaw allows an attacker to crash the … | |
| CVE-2023-52355 | Medium | 1.8% | 7.5 | An out-of-memory flaw was found in libtiff that could be triggered by passing a … | |
| CVE-2011-4088 | Medium | 1.6% | 7.5 | ABRT might allow attackers to obtain sensitive information from crash reports. | |
| CVE-2024-1132 | Medium | 1.6% | 8.1 | A flaw was found in Keycloak, where it does not properly validate URLs included … | |
| CVE-2023-4853 | Medium | 1.4% | 8.1 | A flaw was found in Quarkus where HTTP security policies are not sanitizing cert… | |
| CVE-2025-6021 | Medium | 1.4% | 7.5 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in… | |
| CVE-2025-12543 | Medium | 1.4% | 9.6 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBo… | |
| CVE-2026-42009 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Data… | |
| CVE-2026-1584 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this … | |
| CVE-2025-7424 | Medium | 1.2% | 7.5 | A flaw was found in the libxslt library. The same memory field, psvi, is used fo… | |
| CVE-2024-5154 | Medium | 1.2% | 8.1 | A flaw was found in cri-o. A malicious container can create a symbolic link to a… | |
| CVE-2026-4424 | Medium | 1.2% | 7.5 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exist… | |
| CVE-2022-1011 | Medium | 1.2% | 7.8 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way… | |
| CVE-2023-50781 | Medium | 1.1% | 7.5 | A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt … | |
| CVE-2026-5121 | Medium | 1.1% | 7.5 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerabi… | |
| CVE-2026-42010 | Medium | 1.1% | 7.1 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adlem… | |
| CVE-2023-5379 | Medium | 1.0% | 7.5 | A flaw was found in Undertow. When an AJP request is sent that exceeds the max-h… | |
| CVE-2026-35092 | Medium | 1.0% | 7.5 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's jo… | |
| CVE-2026-46625 | Medium | 0.9% | 7.5 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior t… |
Page 1 of 8
Next →