VulnSea

redhat has 136 CVEs on record between 2010 and 2026. Cadence is steady at roughly 45 per quarter. The busiest recent month was July 2026 with 24. The median CVSS is 6.5 (medium), with 4 rated critical. 6% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 3915 days (7 cases). The dominant weakness classes are CWE-862 (9) and CWE-787 (7). Most affected products: build_of_keycloak (44), openshift_container_platform (15), enterprise_linux (7).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
6% vs 1% corpus
Median CVSS
6.5
Publish → KEV
3915 d median(7)
Last 90 days
45 prev 36

Products

  • build_of_keycloak 44
  • openshift_container_platform 15
  • enterprise_linux 7
  • jboss_enterprise_application_platform 6
  • keycloak 6
  • advanced_cluster_management_for_kubernetes 5
136
Total CVEs
4
Critical
7
CISA KEV
8
Exploited

redhat vulnerabilities

CVEs affecting redhat, newest first. Open any entry for full detail, references, and exploit status.

136 CVEsRSS

CVE-2023-4061Medium· 6.5
2y ago

A flaw was found in wildfly-core

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from the Wildfly system. This issue could allow a malicious user to access the system and ob…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.83%via NVD
CVE-2023-3384Medium· 5.4
3y ago

A flaw was found in the Quay registry

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an imag…

▾ Sunlitredhat · quayEPSS 0.48%via NVD
CVE-2023-1380High· 7.1
3y ago

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buf…

▾ Twilightredhat · enterprise_linuxEPSS 17%via NVD
CVE-2022-0330High· 7.8
4y ago

A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU

A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the s…

▾ Twilightredhat · codeready_linux_builderEPSS 0.38%via NVD
CVE-2022-27666High· 7.8PoC
4y ago

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c

A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privileg…

▾ Midnightredhat · virtualizationEPSS 5.5%via NVD
CVE-2022-1011High· 7.8PoC
4y ago

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write()

A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation.

▾ Midnightredhat · build_of_quarkusEPSS 1.2%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-3501High· 7.1
5y ago

A flaw was found in the Linux kernel in versions before 5.12

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The hig…

▾ Twilightredhat · virtualizationEPSS 0.37%via NVD
CVE-2011-4088High· 7.5
6y ago

ABRT might allow attackers to obtain sensitive information from crash reports.

ABRT might allow attackers to obtain sensitive information from crash reports.

▾ Twilightredhat · automatic_bug_reporting_toolEPSS 1.6%via NVD
CVE-2019-10219Medium· 6.1PoC
6y ago

A vulnerability was found in Hibernate-Validator

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS a…

▾ Twilightredhat · hibernate_validatorEPSS 2.2%via NVD
CVE-2015-1862High· 7.0PoC
8y ago

The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.

The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.

▾ Midnightredhat · automatic_bug_reporting_toolEPSS 3.0%via NVD
CVE-2017-12149Critical· 9.8CISA KEVPoC
8y ago

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserializatio…

▾ Hadalredhat · jboss_enterprise_application_platformEPSS 91%via NVD
CVE-2015-5287High· 7.8CISA KEVPoC
10y ago

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/a…

▾ Abyssalredhat · automatic_bug_reporting_toolEPSS 5.0%via NVD
CVE-2015-3246Medium· 5.1CISA KEVPoC
11y ago

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an erro…

▾ Midnightredhat · libuserEPSS 8.8%via NVD
CVE-2010-1428High· 7.5CISA KEVPoC
16y ago

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allow…

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allow…

▾ Abyssalredhat · jboss_enterprise_application_platformEPSS 62%via NVD
CVE-2010-0738Medium· 5.3CISA KEVPoC
16y ago

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows …

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows …

▾ Midnightredhat · jboss_enterprise_application_platformEPSS 79%via NVD
redhat vulnerabilities (CVEs) — page 5 · VulnSea