Where
AND
-Infinity
0

Vendor Risk Score

See how redhat compares to other vendors in security performance

View Risk Score →

Software

redhat enterprise linux
466
redhat enterprise linux desktop
303
redhat enterprise linux server
303
redhat enterprise linux workstation
290
redhat enterprise linux server aus
209
redhat enterprise linux server tus
171
redhat enterprise linux eus
136
redhat enterprise linux server eus
121
redhat openshift container platform
101
redhat linux
100
redhat jboss enterprise application platform
59
redhat enterprise linux for ibm z systems
42
redhat enterprise linux for power little endian
39
redhat enterprise linux for power little endian eus
39
redhat enterprise linux for ibm z systems eus
38
redhat single sign-on
35
redhat virtualization
34
redhat build of keycloak
33
redhat enterprise linux server for power little endian update services for sap solutions
32
redhat software collections
29
redhat virtualization host
28
redhat satellite
24
redhat openstack
23
redhat enterprise linux for arm 64
21
redhat enterprise linux for arm 64 eus
21
redhat linux advanced workstation
21
redhat enterprise linux for real time
19
redhat jboss core services
18
redhat codeready linux builder
17
redhat hardened images
17
redhat enterprise linux for real time for nfv
16
redhat enterprise linux server update services for sap solutions
16
redhat fedora core
16
redhat enterprise linux update services for sap solutions
15
redhat openshift service mesh
15
redhat enterprise linux aus
14
redhat codeready linux builder for ibm z systems eus
13
redhat enterprise linux for power big endian
13
redhat keycloak
13
redhat codeready linux builder for arm64 eus
12
redhat codeready linux builder for power little endian eus
12
redhat jboss enterprise web server
12
redhat openshift
12
redhat undertow
12
redhat codeready linux builder eus
11
redhat enterprise linux hpc node
11
redhat enterprise linux for real time for nfv tus
10
redhat enterprise linux for real time tus
10
redhat enterprise mrg
10
redhat quay
10

Keycloak KeycloakKeycloak-services: keycloak-services: saml onetimeuse assertion replay in idp-initiated broker flow

Risk 60
Severity
8.1
First published (updated )

Keycloak KeycloakKeycloak-services: keycloak-services: fgap v2 group assignment bypass during user creation

Risk 66
Severity
7.2
First published (updated )

koku-metrics-operatorProject-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address

Risk 47
Severity
7.6
First published (updated )

Microsoft Keycloak social identity provider in Keycloak (Microsoft external identity provider)Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant

Risk 60
Severity
8.1
First published (updated )

Keycloak Keycloak Google Identity Provider (external access-token exchange)Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images

Risk 51
Severity
7.1
First published (updated )

redhat Enterprise LinuxGimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images

Risk 68
Severity
7.8
First published (updated )

redhat Build Of KeycloakKeycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers

Risk 60
Severity
8.1
First published (updated )

redhat Enterprise Linux389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing

Risk 43
Severity
7.5
First published (updated )

redhat Build Of KeycloakKeycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Build Of KeycloakKeycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation

Risk 79
Severity
8.8
First published (updated )

libssh libsshLibssh: libssh: stack buffer overflow in sftp server longname construction

Risk 68
Severity
7.3
First published (updated )

redhat Enterprise LinuxLibssh: libssh: integrity downgrade via openssl aes-gcm tag verification

Risk 46
Severity
7.5
First published (updated )

libssh libsshLibssh: libssh: authentication bypass via missing gssapi principal check

Risk 83
Severity
8.8
First published (updated )

libssh libsshLibssh: libssh: denial of service via automatic certificate authentication loop

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxLibssh: libssh: use-after-free via data callbacks on closed channels

Risk 46
Severity
7.5
First published (updated )

GIMP GIMPGimp: gimp: integer overflow in read_rle_channel()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxGimp: gimp: stack buffer overflow in pnmscanner_gettoken()

Risk 68
Severity
7.8
First published (updated )

redhat Enterprise LinuxYelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Risk 40
Severity
7.1
First published (updated )

Linux Linux kernelmm/list_lru: drain before clearing xarray entry on reparent

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Linux Linux kerneldrm/gem: Try to fix change_handle ioctl, attempt 4

Risk 69
Severity
7.8
First published (updated )

redhat Enterprise LinuxGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise LinuxGlib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"

Risk 64
Severity
8.6
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"

Risk 54
Severity
8.2
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()

Risk 54
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat Enterprise LinuxGlib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime

Risk 43
Severity
7.5
First published (updated )

redhat Enterprise Linuxice: fix double-free of tx_buf skb

Risk 69
Severity
7.8
First published (updated )

Linux Linux kernelnetfilter: nat: use kfree_rcu to release ops

Risk 69
Severity
7.8
First published (updated )

redhat Enterprise LinuxGlib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()

Risk 54
Severity
8.2
First published (updated )

Kubevirt virt-handlerKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption

Risk 47
Severity
7.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203