redhat

5,618 tracked vulnerabilities.

CVE-2019-10169 MEDIUM
Keycloak < 8.0.0 - Authenticated Remote Code Execution via UMA Policy Script Injection
May 08, 2020
CVSS 6.6
EPSS 0.01
CVE-2019-19348 HIGH
openshift/apb-base <4.3.5,4.2.21,4.1.37,3.11.188-4 - Privilege Esca...
Apr 02, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19346 HIGH
openshift/mariadb-apb <4.3.5,4.2.21,4.1.37,3.11.188-4 - Privilege E...
Apr 02, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-14905 MEDIUM
Ansible Engine < 2.7.16 - OS Command Injection via nxos_file_copy Module
Mar 31, 2020
CVSS 5.6
EPSS 0.00
CVE-2019-10180 LOW
dogtagpki 10.0-10.8.2 - Stored Cross-Site Scripting in Token Processing Service
Mar 31, 2020
CVSS 2.4
EPSS 0.01
CVE-2019-19345 HIGH
openshift/mediawiki-apb <4.3.0 - Privilege Escalation
Mar 20, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-10221 MEDIUM
pki-core 10.x.x - XSS
Mar 20, 2020
CVSS 4.3
EPSS 0.01
CVE-2019-10179 MEDIUM
pki-core <10 - XSS
Mar 20, 2020
CVSS 4.3
EPSS 0.00
CVE-2019-19336 MEDIUM
oVirt Engine < 4.3.8 - Cross-Site Scripting via OAuth Authorization Endpoint
Mar 19, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-20485 MEDIUM
libvirt < 6.0.0 - Denial of Service via Guest Agent Query Monitor Job
Mar 19, 2020
CVSS 5.7
EPSS 0.00
CVE-2019-19355 HIGH
openshift/ocp-release-operator-sdk - Privilege Escalation
Mar 18, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19351 HIGH
openshift/jenkins - Privilege Escalation
Mar 18, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-19335 MEDIUM
OpenShift 4.2 - Unprotected Credential Exposure via World-Readable Auth Directory
Mar 18, 2020
CVSS 4.4
EPSS 0.00
CVE-2019-10146 MEDIUM
pki-core <10 - XSS
Mar 18, 2020
CVSS 4.7
EPSS 0.00
CVE-2019-14887 CRITICAL
Wildfly <7.2.5 - Info Disclosure
Mar 16, 2020
CVSS 9.1
EPSS 0.00
CVE-2019-14886 MEDIUM
Red Hat Decision Manager and Process Automation Manager - Cleartext Storage of Sensitive Information in Security Context
Mar 05, 2020
CVSS 6.5
EPSS 0.00
CVE-2019-14892 CRITICAL
jackson-databind < 2.6.7.3 - Remote Code Execution via Polymorphic Deserialization
Mar 02, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-19921 HIGH
runc <1.0.0-rc9 - Privilege Escalation
Feb 12, 2020
CVSS 7.0
EPSS 0.00
CVE-2019-15606 CRITICAL
Node.js 10.0.0-10.18.1, 13.0.0-13.7.0 - Authorization Bypass via HTTP Header Trailing Whitespace
Feb 07, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-15605 CRITICAL
Node.js 10.0.0-10.18.9, 13.0.0-13.7.0 - HTTP Request Smuggling via Malformed Transfer-Encoding
Feb 07, 2020
CVSS 9.8
EPSS 0.32
CVE-2019-15604 HIGH
Node.js 10.0.0-10.18.9, 13.0.0-13.7.9 - Denial of Service via Crafted X.509 Certificate
Feb 07, 2020
CVSS 7.5
EPSS 0.04
CVE-2019-20445 CRITICAL
Netty < 4.1.44 - HTTP Request Smuggling via Duplicate Content-Length Header
Jan 29, 2020
CVSS 9.1
EPSS 0.04
CVE-2019-20444 CRITICAL
Netty < 4.1.44 - HTTP Request Smuggling via Malformed HTTP Header
Jan 29, 2020
CVSS 9.1
EPSS 0.18
CVE-2019-17570 CRITICAL
Apache XML-RPC - Remote Code Execution via Untrusted Deserialization in XmlRpcResponseParser
Jan 23, 2020
CVSS 9.8
EPSS 0.71
CVE-2019-14885 MEDIUM
JBoss Enterprise Application Platform < 7.2.6 - Sensitive Information Disclosure in Log Files via CLI Reload Command
Jan 23, 2020
CVSS 4.3
EPSS 0.00