Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.37%—Openstack Python-keystoneclient1/10/201316/6/2026
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
ModificadaMedia (6.5)1.9%—Openstack KeystoneFedoraproject FedoraCanonical Ubuntu LinuxRedhat Openstack30/9/201316/6/2026
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
ModificadaMedia (5)2.7%—Openstack Keystone23/9/201316/6/2026
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
ModificadaBaja (3.5)1.5%—Openstack Compute16/9/201316/6/2026
The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.
ModificadaBaja (2.1)0.41%—Openstack Cinder16/9/201316/6/2026
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)2.6%—Openstack CinderCanonical Ubuntu Linux16/9/201316/6/2026
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix…
ModificadaAlta (7.5)2.4%—Redhat OpenstackTheforeman Foreman16/9/201316/6/2026
app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.
ModificadaMedia (5)2.4%—Redhat OpenstackTheforeman Foreman16/9/201316/6/2026
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
ModificadaMedia (4.3)2.7%—Openstack HavanaOpenstack Compute16/9/201316/6/2026
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.
ModificadaMedia (6)1.8%—Openstack Nova16/9/201316/6/2026
OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to obtain sensitive information (flavor properties), boot arbitrary flavors, and possibly have other unspecified impacts by guessing the flavor…
ModificadaMedia (5.8)0.99%—Openstack Python GlanceclientOpensuse28/8/201316/6/2026
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to…
ModificadaMedia (4)1.7%—Openstack FolsomOpenstack GrizzlyOpenstack HavanaOpenstack Swift20/8/201316/6/2026
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
ModificadaAlta (7.5)1.9%—Openstack FolsomOpenstack GrizzlyOpenstack HavanaOpensuse20/8/201316/6/2026
XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
ModificadaMedia (4.3)3.1%—Openstack Keystone20/8/201316/6/2026
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
ModificadaMedia (6)25%💥 ExploitRedhat OpenstackTheforeman Foreman31/7/201316/6/2026
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.
ModificadaMedia (6)21%💥 ExploitRedhat OpenstackTheforeman Foreman31/7/201316/6/2026
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.
ModificadaAlta (7.5)3.2%—Google ChromeRedhat OpenstackDebian LinuxNodejs Node.js31/7/201316/6/2026
Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
ModificadaBaja (2.1)0.39%—Openstack FolsomOpenstack GrizzlyOpenstack Havana9/7/201316/6/2026
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.
ModificadaMedia (6)2.5%—Openstack Keystone21/5/201316/6/2026
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
ModificadaBaja (2.1)0.61%💥 PoCOpenstack Keystone21/5/201316/6/2026
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
ModificadaBaja (2.1)0.44%—Openstack Devstack21/5/201316/6/2026
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
ModificadaMedia (5)1.8%—Openstack Keystone12/4/201316/6/2026
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
ModificadaMedia (6.5)3.2%—Openstack Keystone12/4/201330/7/2026
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
ModificadaMedia (6.1)0.45%—Redhat Openstack EssexRedhat Openstack FolsomRedhat Packstack10/4/201316/6/2026
A flaw was found in PackStack. This vulnerability allows a local user to modify deployed systems by changing the answer file, which is created in insecure directories such as /tmp or the current working directory. This insecure file creation could lead to unauthorized system modifications.
ModificadaBaja (2.1)0.39%—Redhat Openstack EssexRedhat Openstack Folsom10/4/201316/6/2026
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.