Записи OpenShift
47 опубликованных записей вендора openshift.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 93,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-91 XML Injection (aka Blind XPath Injection)4
- CWE-125 Out-of-bounds Read3
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')2
- CWE-130 Improper Handling of Length Parameter Inconsistency2
- CWE-122 Heap-based Buffer Overflow2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
47 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-22797Эксплойта нет | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1openstack · keystonemiddleware · CWE-290 | Критическая9,9 | — | 0,7 % | 19 янв. 2026 г. |
37Наблюдать | CVE-2026-44990Эксплойта нет | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`apostrophecms · sanitize-html · CWE-79 | Критическая9,3 | — | 0,7 % | 12 июн. 2026 г. |
36Наблюдать | CVE-2026-9277Proof of concept | shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`CWE-77 | Критическая9,2 | — | 1,0 % | 22 мая 2026 г. |
36Наблюдать | CVE-2025-10263Эксплойта нет | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-arm · c1-ultra · CWE-362 | Критическая9,1 | — | 0,5 % | 9 июн. 2026 г. |
34Наблюдать | CVE-2026-31812Эксплойта нет | Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsingquinn-rs · quinn · CWE-248 | Высокая8,7 | — | 0,9 % | 10 мар. 2026 г. |
34Наблюдать | CVE-2026-41673Эксплойта нет | xmldom: Denial of service via uncontrolled recursion in XML serializationxmldom · xmldom · CWE-674 | Высокая8,7 | — | 0,9 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-5367Эксплойта нет | Ovn: ovn: information disclosure via crafted dhcpv6 packetsred hat · fast datapath for red hat enterprise linux 10 · CWE-130 | Высокая8,6 | — | 0,9 % | 24 апр. 2026 г. |
34Наблюдать | CVE-2026-35469Эксплойта нет | SpdyStream: DOS on CRImoby · spdystream · CWE-770 | Высокая8,7 | — | 0,8 % | 16 апр. 2026 г. |
34Наблюдать | CVE-2026-12143Эксплойта нет | form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)form-data · form-data · CWE-93 | Высокая8,7 | — | 0,7 % | 12 июн. 2026 г. |
34Наблюдать | CVE-2026-41674Эксплойта нет | xmldom: XML injection through unvalidated DocumentType serializationxmldom · xmldom · CWE-91 | Высокая8,7 | — | 0,7 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-41672Эксплойта нет | xmldom: XML node injection through unvalidated comment serializationxmldom · xmldom · CWE-91 | Высокая8,7 | — | 0,7 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-41675Эксплойта нет | xmldom: XML node injection through unvalidated processing instruction serializationxmldom · xmldom · CWE-91 | Высокая8,7 | — | 0,6 % | 7 мая 2026 г. |
34Наблюдать | CVE-2026-49851Эксплойта нет | Mistune: Potential DoS via quadratic-time parsing in parse_link_textlepture · mistune · CWE-400 | Высокая8,7 | — | 0,6 % | 24 июн. 2026 г. |
34Наблюдать | CVE-2026-10649Эксплойта нет | Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressionred hat · red hat enterprise linux 10 · CWE-190 | Высокая8,6 | — | 0,6 % | 16 июн. 2026 г. |
34Наблюдать | CVE-2026-41163Эксплойта нет | bubblewrap vulnerable to privilege escalation in setuid mode via ptracecontainers · bubblewrap · CWE-269 | Высокая8,7 | — | 0,4 % | 9 мая 2026 г. |
33Наблюдать | CVE-2025-13878Эксплойта нет | Malformed BRID/HHIT records can cause named to terminate unexpectedlyisc · bind 9 · CWE-617 | Высокая7,5 | — | 9,2 % | 21 янв. 2026 г. |
33Наблюдать | CVE-2026-4892Эксплойта нет | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code withdnsmasq · dnsmasq · CWE-122 | Высокая8,4 | — | 0,3 % | 11 мая 2026 г. |
33Наблюдать | CVE-2026-54369Эксплойта нет | acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functionsacl project · acl · CWE-59 | Высокая8,4 | — | 0,2 % | 29 июн. 2026 г. |
33Наблюдать | CVE-2026-54371Эксплойта нет | attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattrattr project · attr · CWE-59 | Высокая8,4 | — | 0,2 % | 29 июн. 2026 г. |
32Наблюдать | CVE-2026-41316Эксплойта нет | ERB has an @_init deserialization guard bypass via def_module / def_method / def_classruby · erb · CWE-693 | Высокая8,1 | — | 1,3 % | 23 апр. 2026 г. |
31Наблюдать | CVE-2026-6893Эксплойта нет | Dracut: dracut: root code execution via dhcp options command injectionred hat · red hat enterprise linux 10 · CWE-78 | Высокая7,5 | — | 3,1 % | 10 июн. 2026 г. |
31Наблюдать | CVE-2026-3238Эксплойта нет | Samba: denial of service against ad dc wins serverred hat · red hat enterprise linux 10 · CWE-476 | Высокая7,5 | — | 2,0 % | 8 июн. 2026 г. |
31Наблюдать | CVE-2026-11332Эксплойта нет | Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code executionred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-88 | Высокая7,8 | — | 0,2 % | 5 июн. 2026 г. |
31Наблюдать | CVE-2026-3842Эксплойта нет | Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob writered hat · red hat enterprise linux 10 · CWE-787 | Высокая7,8 | — | 0,2 % | 15 июл. 2026 г. |
31Наблюдать | CVE-2026-12505Эксплойта нет | Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcallred hat · red hat enterprise linux 10 · CWE-250 | Высокая7,8 | — | 0,2 % | 18 июн. 2026 г. |
- CVE-2026-2279739Наблюдать
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %openstack · keystonemiddleware19 янв. 2026 г.
- CVE-2026-4499037Наблюдать
Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %apostrophecms · sanitize-html12 июн. 2026 г.
- CVE-2026-927736Наблюдать
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
КритическаяCVSS 9,2Proof of conceptEPSS 1 %22 мая 2026 г.
- CVE-2025-1026336Наблюдать
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %arm · c1-ultra9 июн. 2026 г.
- CVE-2026-3181234Наблюдать
Quinn affected by unauthenticated remote DoS via panic in QUIC transport parameter parsing
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %quinn-rs · quinn10 мар. 2026 г.
- CVE-2026-4167334Наблюдать
xmldom: Denial of service via uncontrolled recursion in XML serialization
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom7 мая 2026 г.
- CVE-2026-536734Наблюдать
Ovn: ovn: information disclosure via crafted dhcpv6 packets
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %red hat · fast datapath for red hat enterprise linux 1024 апр. 2026 г.
- CVE-2026-3546934Наблюдать
SpdyStream: DOS on CRI
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %moby · spdystream16 апр. 2026 г.
- CVE-2026-1214334Наблюдать
form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %form-data · form-data12 июн. 2026 г.
- CVE-2026-4167434Наблюдать
xmldom: XML injection through unvalidated DocumentType serialization
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom7 мая 2026 г.
- CVE-2026-4167234Наблюдать
xmldom: XML node injection through unvalidated comment serialization
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom7 мая 2026 г.
- CVE-2026-4167534Наблюдать
xmldom: XML node injection through unvalidated processing instruction serialization
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom7 мая 2026 г.
- CVE-2026-4985134Наблюдать
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %lepture · mistune24 июн. 2026 г.
- CVE-2026-1064934Наблюдать
Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 1016 июн. 2026 г.
- CVE-2026-4116334Наблюдать
bubblewrap vulnerable to privilege escalation in setuid mode via ptrace
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %containers · bubblewrap9 мая 2026 г.
- CVE-2025-1387833Наблюдать
Malformed BRID/HHIT records can cause named to terminate unexpectedly
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %isc · bind 921 янв. 2026 г.
- CVE-2026-489233Наблюдать
A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %dnsmasq · dnsmasq11 мая 2026 г.
- CVE-2026-5436933Наблюдать
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %acl project · acl29 июн. 2026 г.
- CVE-2026-5437133Наблюдать
attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %attr project · attr29 июн. 2026 г.
- CVE-2026-4131632Наблюдать
ERB has an @_init deserialization guard bypass via def_module / def_method / def_class
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %ruby · erb23 апр. 2026 г.
- CVE-2026-689331Наблюдать
Dracut: dracut: root code execution via dhcp options command injection
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %red hat · red hat enterprise linux 1010 июн. 2026 г.
- CVE-2026-323831Наблюдать
Samba: denial of service against ad dc wins server
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %red hat · red hat enterprise linux 108 июн. 2026 г.
- CVE-2026-1133231Наблюдать
Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %red hat · red hat ansible automation platform 2.5 for rhel 85 июн. 2026 г.
- CVE-2026-384231Наблюдать
Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 1015 июл. 2026 г.
- CVE-2026-1250531Наблюдать
Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 1018 июн. 2026 г.