redhat

5,618 tracked vulnerabilities.

CVE-2025-57853 MEDIUM
Web-terminal: privilege escalation via excessive /etc/passwd permissions
Apr 08, 2026
CVSS 6.4
EPSS 0.00
CVE-2025-57851 MEDIUM
Mce: privilege escalation via excessive /etc/passwd permissions
Apr 08, 2026
CVSS 6.4
EPSS 0.00
CVE-2025-57847 MEDIUM
Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions
Apr 08, 2026
CVSS 6.4
EPSS 0.00
CVE-2025-14821 HIGH
Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows
Apr 07, 2026
CVSS 7.8
EPSS 0.00
CVE-2025-12805 HIGH
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
Mar 26, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-12801 MEDIUM
nfs-utils - Privilege Escalation
Mar 04, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-12150 LOW
Keycloak < 26.4.4 - Improper Verification of Cryptographic Signature via WebAuthn Attestation Bypass
Feb 27, 2026
CVSS 3.1
EPSS 0.00
CVE-2025-9909 MEDIUM
Red Hat Ansible Automation Platform - Auth Bypass
Feb 27, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-9908 MEDIUM
Red Hat Ansible Automation Platform - Info Disclosure
Feb 27, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-9907 MEDIUM
Red Hat Ansible Automation Platform - Info Disclosure
Feb 27, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-9572 MEDIUM
Foreman 1.22.0-3.16.1 - Incorrect Authorization via GraphQL API
Feb 27, 2026
CVSS 5.0
EPSS 0.00
CVE-2025-12543 CRITICAL
Undertow HTTP Server - Malformed Host Header Cache Poisoning
Jan 07, 2026
CVSS 9.6
EPSS 0.00
CVE-2025-14874 HIGH
Nodemailer < 7.0.11 - Denial of Service via Crafted Email Address Header
Dec 18, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-14512 MEDIUM
glib < 2.86.3 - Heap Buffer Overflow and Denial of Service via GIO escape_byte_string() Integer Overflow
Dec 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-14087 MEDIUM
GLib < 2.86.3 - Heap Corruption via GVariant Parser Buffer Underflow
Dec 10, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-14010 MEDIUM
community.general - Sensitive Credential Exposure via Verbose Debug Output
Dec 04, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-13601 HIGH
Red Hat CodeReady Linux Builder - Heap-Based Buffer Overflow via g_escape_uri_string()
Nov 26, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-9784 HIGH
Red Hat build of Apache Camel for Spring Boot - Denial of Service via MadeYouReset Attack
Sep 02, 2025
CVSS 7.5
EPSS 0.02
CVE-2025-8419 MEDIUM
Keycloak < 26.2.8 - SMTP Injection via Email Registration
Aug 06, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-8283 LOW
netavark - Info Disclosure
Jul 28, 2025
CVSS 3.7
EPSS 0.00
CVE-2025-7784 MEDIUM
Red Hat build of Keycloak - Privilege Escalation via Fine-Grained Admin Permissions
Jul 18, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7519 MEDIUM
polkit - Buffer Overflow
Jul 14, 2025
CVSS 6.7
EPSS 0.00
CVE-2025-53862 LOW
Ansible Automation Platform - Unauthenticated Exposure of Sensitive System Information via API Endpoints
Jul 11, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-53861 LOW
Ansible Automation Platform - Cleartext Transmission of Sensitive Cookies
Jul 11, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-7365 HIGH
Keycloak - Authenticated Account Takeover via Identity Provider Login Email Verification
Jul 10, 2025
CVSS 7.1
EPSS 0.00