Skip to content
Noroxi

OpenShift records

47 published records for vendor openshift.

All records

47 records
  • An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1

    CriticalCVSS 9.9No exploitEPSS 1%

    openstack · keystonemiddlewareJan 19, 2026

  • Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

    CriticalCVSS 9.3No exploitEPSS 1%

    apostrophecms · sanitize-htmlJun 12, 2026

  • CVE-2026-9277
    36Monitor

    shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`

    CriticalCVSS 9.2Proof of conceptEPSS 1%

    May 22, 2026

  • Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-

    CriticalCVSS 9.1No exploitEPSS 1%

    arm · c1-ultraJun 9, 2026

  • Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing

    HighCVSS 8.7No exploitEPSS 1%

    quinn-rs · quinnMar 10, 2026

  • xmldom: Denial of service via uncontrolled recursion in XML serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • CVE-2026-5367
    34Monitor

    Ovn: ovn: information disclosure via crafted dhcpv6 packets

    HighCVSS 8.6No exploitEPSS 1%

    red hat · fast datapath for red hat enterprise linux 10Apr 24, 2026

  • SpdyStream: DOS on CRI

    HighCVSS 8.7No exploitEPSS 1%

    moby · spdystreamApr 16, 2026

  • form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)

    HighCVSS 8.7No exploitEPSS 1%

    form-data · form-dataJun 12, 2026

  • xmldom: XML injection through unvalidated DocumentType serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • xmldom: XML node injection through unvalidated comment serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • xmldom: XML node injection through unvalidated processing instruction serialization

    HighCVSS 8.7No exploitEPSS 1%

    xmldom · xmldomMay 7, 2026

  • Mistune: Potential DoS via quadratic-time parsing in parse_link_text

    HighCVSS 8.7No exploitEPSS 1%

    lepture · mistuneJun 24, 2026

  • Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression

    HighCVSS 8.6No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jun 16, 2026

  • bubblewrap vulnerable to privilege escalation in setuid mode via ptrace

    HighCVSS 8.7No exploitEPSS 0%

    containers · bubblewrapMay 9, 2026

  • Malformed BRID/HHIT records can cause named to terminate unexpectedly

    HighCVSS 7.5No exploitEPSS 9%

    isc · bind 9Jan 21, 2026

  • CVE-2026-4892
    33Monitor

    A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with

    HighCVSS 8.4No exploitEPSS 0%

    dnsmasq · dnsmasqMay 11, 2026

  • acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions

    HighCVSS 8.4No exploitEPSS 0%

    acl project · aclJun 29, 2026

  • attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr

    HighCVSS 8.4No exploitEPSS 0%

    attr project · attrJun 29, 2026

  • ERB has an @_init deserialization guard bypass via def_module / def_method / def_class

    HighCVSS 8.1No exploitEPSS 1%

    ruby · erbApr 23, 2026

  • CVE-2026-6893
    31Monitor

    Dracut: dracut: root code execution via dhcp options command injection

    HighCVSS 7.5No exploitEPSS 3%

    red hat · red hat enterprise linux 10Jun 10, 2026

  • CVE-2026-3238
    31Monitor

    Samba: denial of service against ad dc wins server

    HighCVSS 7.5No exploitEPSS 2%

    red hat · red hat enterprise linux 10Jun 8, 2026

  • Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

    HighCVSS 7.8No exploitEPSS 0%

    red hat · red hat ansible automation platform 2.5 for rhel 8Jun 5, 2026

  • CVE-2026-3842
    31Monitor

    Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write

    HighCVSS 7.8No exploitEPSS 0%

    red hat · red hat enterprise linux 10Jul 15, 2026

  • Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall

    HighCVSS 7.8No exploitEPSS 0%

    red hat · red hat enterprise linux 10Jun 18, 2026