| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Security 4 | any | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Security 4 | - | cpe:/a:redhat:advanced_cluster_security:4 |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18948 | 9.9 CRITICAL | Feast: feast: unsafe dill deserialization of registry-stored udfs — rce on feature server |
| CVE-2026-14450 | 9.9 CRITICAL | Maas-billing: maas api: privilege escalation via forged http headers due to missing authen |
| CVE-2026-18950 | 8.8 HIGH | Odh-dashboard: odh-dashboard: confused-deputy privilege escalation via unchecked roleref i |
| CVE-2026-18949 | 8.8 HIGH | Odh-dashboard: odh-dashboard: clusterrole grants cluster-wide crud on secrets and rbac man |
| CVE-2026-18951 | 8.8 HIGH | Odh-training-operator-rhel9: [trainer v2 security] trn-02: rhoai overlay aggregates trainj |
| CVE-2026-18617 | 8.8 HIGH | Data-science-pipelines-operator: dspo: mysql dsn parameter injection via customextraparams |
| CVE-2026-13717 | 8.8 HIGH | Rhoai maas: llm-d: maas/llm-d inference gateway: default allowedroutes.namespaces.from: al |
| CVE-2026-18982 | 8.8 HIGH | Odh-training-operator-rhel9: rhoai fork aggregates training job create onto native edit/ad |
| CVE-2026-18608 | 8.7 HIGH | Data-science-pipelines-operator: dspo: operator clusterrole grants pods/exec:*, kubeflow.o |
| CVE-2026-18947 | 8.5 HIGH | Feast: feast: authorization bypass in /materialize endpoints enables dos via unauthorized |
| CVE-2026-71576 | 8.5 HIGH | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source( |
| CVE-2026-59090 | 8.4 HIGH | Gimp: gimp: arbitrary code execution in psd plugin due to unsigned underflow |
| CVE-2026-15467 | 8.1 HIGH | Trustyai-service-operator: trustyai-service-operator: lmevaljob sidecar containers bypass |
| CVE-2026-15581 | 8.0 HIGH | Trustyai-service-operator: trustyai-service-operator: tas internal service bypasses kube-r |
| CVE-2026-63622 | 7.8 HIGH | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-59087 | 7.8 HIGH | Gimp: heap buffer overflow in `file-seattle-filmworks` load — `fread` writes attacker-cont |
| CVE-2026-18941 | 7.7 HIGH | Feast: feast-operator: feast: default authentication mode is no_auth — shared multi-tenant |
| CVE-2026-18621 | 7.6 HIGH | Data-sciences-pipeline: dsp: v1 argo template path accepts arbitrary workflow spec, bypass |
| CVE-2026-19387 | 7.6 HIGH | Gstreamer: gstreamer1-plugins-bad-free: gstreamer: heap out-of-bounds write in adpcmdec im |
| CVE-2026-18611 | 7.5 HIGH | Data-science-pipelines-operator: dspo: cryptographically weak secret generation (math/rand |
Showing top 20 of 33 CVEs. View all on vendor page → →
No comments yet