CVE-2026-86330
- EPSS 2.18%
- Veröffentlicht 28.09.2026 12:18:30
- Zuletzt bearbeitet 30.09.2026 21:17:16
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because th...
CVE-2026-15416
- EPSS 0.28%
- Veröffentlicht 14.07.2026 08:56:29
- Zuletzt bearbeitet 11.08.2026 01:17:20
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker...
CVE-2025-8766
- EPSS 0.17%
- Veröffentlicht 13.03.2026 02:48:19
- Zuletzt bearbeitet 15.07.2026 02:17:54
A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can ...
CVE-2023-48795
- EPSS 93.31%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 12.05.2026 11:16:15
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2021-3979
- EPSS 0.44%
- Veröffentlicht 25.08.2022 20:15:09
- Zuletzt bearbeitet 03.11.2025 19:15:40
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality an...
CVE-2021-4048
- EPSS 2.64%
- Veröffentlicht 08.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:36:47
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application u...