Where
AND
-Infinity
0

Vendor Risk Score

See how redhat compares to other vendors in security performance

View Risk Score →

Software

redhat enterprise linux
449
redhat enterprise linux desktop
301
redhat enterprise linux server
301
redhat enterprise linux workstation
288
redhat enterprise linux server aus
208
redhat enterprise linux server tus
170
redhat enterprise linux eus
135
redhat enterprise linux server eus
121
redhat linux
100
redhat openshift container platform
95
redhat jboss enterprise application platform
55
redhat enterprise linux for ibm z systems
42
redhat enterprise linux for power little endian
39
redhat enterprise linux for power little endian eus
39
redhat enterprise linux for ibm z systems eus
38
redhat virtualization
33
redhat enterprise linux server for power little endian update services for sap solutions
32
redhat single sign-on
30
redhat software collections
29
redhat virtualization host
28
redhat build of keycloak
24
redhat satellite
24
redhat openstack
22
redhat enterprise linux for arm 64
21
redhat enterprise linux for arm 64 eus
21
redhat linux advanced workstation
21
redhat enterprise linux for real time
19
redhat jboss core services
18
redhat codeready linux builder
17
redhat enterprise linux for real time for nfv
16
redhat enterprise linux server update services for sap solutions
16
redhat fedora core
16
redhat enterprise linux update services for sap solutions
15
redhat openshift service mesh
15
redhat enterprise linux aus
14
redhat codeready linux builder for ibm z systems eus
13
redhat enterprise linux for power big endian
13
redhat openshift
13
redhat codeready linux builder for arm64 eus
12
redhat codeready linux builder for power little endian eus
12
redhat jboss enterprise web server
12
redhat undertow
12
redhat codeready linux builder eus
11
redhat enterprise linux hpc node
11
redhat hardened images
11
redhat enterprise linux for real time for nfv tus
10
redhat enterprise linux for real time tus
10
redhat enterprise mrg
10
redhat quay
10
redhat ansible tower
9

GIMP GIMPGimp: gimp: integer overflow in read_rle_channel()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxGimp: gimp: stack buffer overflow in pnmscanner_gettoken()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Risk 40
Severity
7.1
First published (updated )

KubeVirt (virt-handler migration proxy)Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces

Risk 73
Severity
8.5
First published (updated )

Linux Linux kernelmm/list_lru: drain before clearing xarray entry on reparent

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Linux Linux kerneldrm/gem: Try to fix change_handle ioctl, attempt 4

Risk 69
Severity
7.8
First published (updated )

redhat Enterprise LinuxGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

Risk 64
Severity
8.6
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

Risk 54
Severity
8.2
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise Linuxice: fix double-free of tx_buf skb

Risk 69
Severity
7.8
First published (updated )

Linux Linux kernelnetfilter: nat: use kfree_rcu to release ops

Risk 69
Severity
7.8
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()

Risk 54
Severity
8.2
First published (updated )

Kubevirt virt-handlerKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption

Risk 47
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apicurio Apicurio RegistryApicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation

Risk 52
Severity
7.4
First published (updated )

Traefik traefikTraefik - Denial of Service via HTTP/2 Request Handling

Risk 47
Severity
8.7
First published (updated )

Apicurio apicurio-registryApicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos

Risk 55
Severity
8.5
First published (updated )

vscode-java vscode-javaVscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension

Risk 77
Severity
8.8
First published (updated )

Fedoraproject FedoraAbrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Foreman Foreman MCP ServerForeman-mcp-server: mcp server: active session hijacking via insecure session state reuse

Risk 69
Severity
7.8
First published (updated )

Red Hat Windows Machine Config Operator (WMCO)Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft

Risk 72
Severity
8.3
First published (updated )

Red Hat Windows Machine Config OperatorWindows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters

Risk 72
Severity
8.8
First published (updated )

redhat Openshift Service MeshEnvoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification

Risk 46
Severity
7.5
First published (updated )

VMware Spring For Apache KafkaIn Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

Risk 75
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Keycloak KeycloakOrg.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion

Risk 60
Severity
8.1
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat

Risk 73
Severity
7.8
First published (updated )

redhat Enterprise LinuxXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()

Risk 74
Severity
7.8
First published (updated )

redhat Enterprise LinuxXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing

Risk 74
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203