redhat
5,618 tracked vulnerabilities.
CVE-2019-10169
MEDIUM
Keycloak < 8.0.0 - Authenticated Remote Code Execution via UMA Policy Script Injection
May 08, 2020
CVSS 6.6
EPSS 0.01
CVE-2019-19348
HIGH
openshift/apb-base <4.3.5,4.2.21,4.1.37,3.11.188-4 - Privilege Esca...
Apr 02, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19346
HIGH
openshift/mariadb-apb <4.3.5,4.2.21,4.1.37,3.11.188-4 - Privilege E...
Apr 02, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-14905
MEDIUM
Ansible Engine < 2.7.16 - OS Command Injection via nxos_file_copy Module
Mar 31, 2020
CVSS 5.6
EPSS 0.00
CVE-2019-10180
LOW
dogtagpki 10.0-10.8.2 - Stored Cross-Site Scripting in Token Processing Service
Mar 31, 2020
CVSS 2.4
EPSS 0.01
CVE-2019-19345
HIGH
openshift/mediawiki-apb <4.3.0 - Privilege Escalation
Mar 20, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-10221
MEDIUM
pki-core 10.x.x - XSS
Mar 20, 2020
CVSS 4.3
EPSS 0.01
CVE-2019-10179
MEDIUM
pki-core <10 - XSS
Mar 20, 2020
CVSS 4.3
EPSS 0.00
CVE-2019-19336
MEDIUM
oVirt Engine < 4.3.8 - Cross-Site Scripting via OAuth Authorization Endpoint
Mar 19, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-20485
MEDIUM
libvirt < 6.0.0 - Denial of Service via Guest Agent Query Monitor Job
Mar 19, 2020
CVSS 5.7
EPSS 0.00
CVE-2019-19355
HIGH
openshift/ocp-release-operator-sdk - Privilege Escalation
Mar 18, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19351
HIGH
openshift/jenkins - Privilege Escalation
Mar 18, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19335
MEDIUM
OpenShift 4.2 - Unprotected Credential Exposure via World-Readable Auth Directory
Mar 18, 2020
CVSS 4.4
EPSS 0.00
CVE-2019-10146
MEDIUM
pki-core <10 - XSS
Mar 18, 2020
CVSS 4.7
EPSS 0.00
CVE-2019-14887
CRITICAL
Wildfly <7.2.5 - Info Disclosure
Mar 16, 2020
CVSS 9.1
EPSS 0.00
CVE-2019-14886
MEDIUM
Red Hat Decision Manager and Process Automation Manager - Cleartext Storage of Sensitive Information in Security Context
Mar 05, 2020
CVSS 6.5
EPSS 0.00
CVE-2019-14892
CRITICAL
jackson-databind < 2.6.7.3 - Remote Code Execution via Polymorphic Deserialization
Mar 02, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-19921
HIGH
runc <1.0.0-rc9 - Privilege Escalation
Feb 12, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-15606
CRITICAL
Node.js 10.0.0-10.18.1, 13.0.0-13.7.0 - Authorization Bypass via HTTP Header Trailing Whitespace
Feb 07, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-15605
CRITICAL
Node.js 10.0.0-10.18.9, 13.0.0-13.7.0 - HTTP Request Smuggling via Malformed Transfer-Encoding
Feb 07, 2020
CVSS 9.8
EPSS 0.32
CVE-2019-15604
HIGH
Node.js 10.0.0-10.18.9, 13.0.0-13.7.9 - Denial of Service via Crafted X.509 Certificate
Feb 07, 2020
CVSS 7.5
EPSS 0.04
CVE-2019-20445
CRITICAL
Netty < 4.1.44 - HTTP Request Smuggling via Duplicate Content-Length Header
Jan 29, 2020
CVSS 9.1
EPSS 0.04
CVE-2019-20444
CRITICAL
Netty < 4.1.44 - HTTP Request Smuggling via Malformed HTTP Header
Jan 29, 2020
CVSS 9.1
EPSS 0.18
CVE-2019-17570
CRITICAL
Apache XML-RPC - Remote Code Execution via Untrusted Deserialization in XmlRpcResponseParser
Jan 23, 2020
CVSS 9.8
EPSS 0.71
CVE-2019-14885
MEDIUM
JBoss Enterprise Application Platform < 7.2.6 - Sensitive Information Disclosure in Log Files via CLI Reload Command
Jan 23, 2020
CVSS 4.3
EPSS 0.00
Products
enterprise_linux_desktop 1,928
enterprise_linux_server 1,891
enterprise_linux_workstation 1,845
enterprise_linux 1,780
enterprise_linux_server_aus 1,059
enterprise_linux_eus 780
enterprise_linux_server_tus 768
enterprise_linux_server_eus 622
openshift_container_platform 291
jboss_enterprise_application_platform 243
linux 229
satellite 222
openstack 210
enterprise_linux_hpc_node 146
openshift 146
software_collections 137
virtualization 128
enterprise_linux_for_ibm_z_systems 112
single_sign-on 108
enterprise_linux_for_power_little_endian 106
keycloak 98
enterprise_linux_for_power_little_endian_eus 93
enterprise_linux_for_ibm_z_systems_eus 87
enterprise_linux_workstation_supplementary 86
enterprise_linux_desktop_supplementary 84
enterprise_linux_server_supplementary 84
virtualization_host 84
enterprise_linux_server_supplementary_eus 83
enterprise_linux_hpc_node_eus 81
fedora_core 77
Quick Filters