Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.2% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-8578. | |
| Modificada | Baja (3.5) | 1.9% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name. | |
| Modificada | Media (4.3) | 1.7% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2, when used with Heat, allows remote Orchestration template owners or catalogs to inject arbitrary web… | |
| Modificada | Media (4) | 2.0% | — | Redhat OpenstackOpenstack Nova | 31/10/2014 | 17/6/2026 | The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state. | |
| Modificada | Media (4) | 2.8% | — | Openstack NovaRedhat Openstack | 31/10/2014 | 17/6/2026 | OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request. | |
| Modificada | Media (6.5) | 1.9% | — | Openstack Keystone | 26/10/2014 | 17/6/2026 | OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request. | |
| Modificada | Media (4) | 3.0% | — | Openstack Swift | 17/10/2014 | 17/6/2026 | OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined. | |
| Modificada | Media (6.5) | 2.0% | — | Openstack Nova | 15/10/2014 | 17/6/2026 | Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances. | |
| Modificada | Baja (2.1) | 0.53% | — | Openstack CinderOpenstack NovaOpenstack TroveRedhat Openstack | 8/10/2014 | 17/6/2026 | The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log. | |
| Modificada | Baja (2.1) | 0.49% | — | Openstack CinderOpenstack NovaOpenstack TroveRedhat Openstack+1 | 8/10/2014 | 17/6/2026 | The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log. | |
| Modificada | Media (4) | 1.9% | — | Openstack Cinder | 8/10/2014 | 17/6/2026 | The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. | |
| Modificada | Alta (7.6) | 2.5% | — | Openstack Neutron | 7/10/2014 | 17/6/2026 | The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a… | |
| Modificada | Baja (2.7) | 1.7% | — | Openstack Nova | 6/10/2014 | 17/6/2026 | The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability… | |
| Modificada | Media (4.3) | 2.0% | — | Openstack KeystonemiddlewareOpenstack Python-keystoneclient | 2/10/2014 | 17/6/2026 | OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted… | |
| Modificada | Media (4) | 2.1% | — | Openstack NeutronCanonical Ubuntu Linux | 2/10/2014 | 17/6/2026 | OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors. | |
| Modificada | Media (4) | 2.1% | — | Openstack KeystoneCanonical Ubuntu LinuxRedhat Openstack | 2/10/2014 | 17/6/2026 | The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field. | |
| Modificada | Media (4) | 2.1% | — | Openstack Image Registry AND Delivery Service (glance)Canonical Ubuntu Linux | 25/8/2014 | 17/6/2026 | OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large… | |
| Modificada | Media (4.9) | 1.5% | — | Openstack KeystoneCanonical Ubuntu Linux | 25/8/2014 | 17/6/2026 | OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain. | |
| Modificada | Media (4.9) | 1.5% | — | Openstack KeystoneCanonical Ubuntu Linux | 25/8/2014 | 17/6/2026 | The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/. | |
| Modificada | Media (4.9) | 1.6% | — | Openstack KeystoneCanonical Ubuntu Linux | 25/8/2014 | 17/6/2026 | The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token. | |
| Modificada | Baja (3.5) | 2.1% | — | Openstack HorizonOpensuse | 22/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name. | |
| Modificada | Media (5) | 2.8% | — | Redhat OpenstackCanonical Ubuntu LinuxOpenstack NeutronOpenstack Oslo+2 | 19/8/2014 | 17/6/2026 | The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request). | |
| Modificada | Media (4.3) | 2.0% | — | Openstack Nova | 7/8/2014 | 17/6/2026 | api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance… | |
| Modificada | Media (4) | 2.2% | — | Openstack Neutron | 23/7/2014 | 17/6/2026 | OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs. | |
| Modificada | Baja (3.5) | 1.7% | — | Openstack NeutronCanonical Ubuntu Linux | 11/7/2014 | 17/6/2026 | The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router. |