Where
-Infinity
0

Vendor Risk Score

See how redhat compares to other vendors in security performance

View Risk Score →

Software

redhat enterprise linux
1237
redhat enterprise linux desktop
887
redhat enterprise linux server
838
redhat enterprise linux workstation
806
redhat enterprise linux server aus
549
redhat enterprise linux server tus
435
redhat enterprise linux eus
385
redhat enterprise linux server eus
320
redhat linux
237
redhat openshift container platform
193
redhat jboss enterprise application platform
142
redhat satellite
108
redhat openstack
89
redhat fedora core
81
redhat enterprise linux for ibm z systems
78
redhat enterprise linux for power little endian
70
redhat linux advanced workstation
68
redhat build of keycloak
64
redhat enterprise linux for power little endian eus
64
redhat enterprise linux for ibm z systems eus
63
redhat single sign-on
63
redhat virtualization
63
redhat software collections
59
redhat virtualization host
52
redhat enterprise linux server for power little endian update services for sap solutions
46
redhat openshift
40
redhat enterprise linux for arm 64
39
redhat keycloak
37
redhat enterprise linux for real time
36
redhat enterprise mrg
35
redhat enterprise linux for arm 64 eus
33
redhat ansible tower
32
redhat enterprise linux hpc node
32
redhat hardened images
31
redhat jboss core services
31
redhat enterprise linux for real time for nfv
30
redhat undertow
29
redhat codeready linux builder
25
redhat enterprise linux for power big endian
25
redhat enterprise linux server update services for sap solutions
24
redhat libvirt
24
redhat jboss enterprise web server
23
redhat enterprise linux aus
22
redhat enterprise linux for scientific computing
22
redhat directory server
21
redhat enterprise linux update services for sap solutions
21
redhat fuse
21
redhat jboss fuse
21
redhat ansible automation platform
20
redhat ansible
19

guardrails-detectorsGuardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex

Risk 38
Severity
6.5
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification

Risk 20
Severity
3.7
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption

Risk 26
Severity
4.4
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn

Risk 27
Severity
5.3
First published (updated )

GIMP GIMPGimp: gimp: integer overflow in read_rle_channel()

Risk 68
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGimp: gimp: denial of service via integer overflow in playstation tim loader

Risk 31
Severity
5.5
First published (updated )

redhat Enterprise LinuxGimp: gimp: stack buffer overflow in pnmscanner_gettoken()

Risk 68
Severity
7.8
First published (updated )

Keycloak keycloak-admin-uiKeycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions

Risk 22
Severity
4.3
First published (updated )

redhat Enterprise LinuxP11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing

Risk 36
Severity
6.2
First published (updated )

redhat Enterprise LinuxYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxUtil-linux: util-linux: heap use-after-free in libblkid nested partition probing

Risk 45
Severity
6.8
First published (updated )

redhat Enterprise LinuxSpice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow

Risk 35
Severity
5.1
First published (updated )

redhat Enterprise LinuxSpice-vdagent: path traversal in file transfer via unsanitized filename

Risk 26
Severity
4.4
First published (updated )

KubeVirtVirt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled

Risk 32
Severity
4.9
First published (updated )

KubeVirt (virt-handler migration proxy)Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces

Risk 73
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

KubeVirtKubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service

Risk 20
Severity
3.8
First published (updated )

KubeVirt virt-apiVirt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip

Risk 39
Severity
6.4
First published (updated )

Linux Linux kernelmm/list_lru: drain before clearing xarray entry on reparent

Risk 69
Severity
7.8
First published (updated )

Linux Linux kerneldrm/gem: Try to fix change_handle ioctl, attempt 4

Risk 69
Severity
7.8
First published (updated )

Kubevirt virt-handlerKubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher

Risk 28
Severity
4.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"

Risk 66
Severity
9.1
First published (updated )

redhat Enterprise LinuxGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

Risk 64
Severity
8.6
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

Risk 54
Severity
8.2
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise Linuxice: fix double-free of tx_buf skb

Risk 69
Severity
7.8
First published (updated )

Linux Linux kernelipv6: fix possible UAF in icmpv6_rcv()

Risk 86
Severity
9.8
First published (updated )

Linux Linux kernelnetfilter: conntrack: remove sprintf usage

Risk 86
Severity
9.8
First published (updated )

Linux Linux kernelnetfilter: nat: use kfree_rcu to release ops

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203