Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
56 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.64% | — | Redhat Ovirt-engine | 13/2/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request. | |
| Modificada | Media (4.3) | 1.3% | — | Ovirt | 8/9/2014 | 17/6/2026 | The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page. | |
| Modificada | Media (6.8) | 1.8% | — | OvirtRedhat Ovirt-engine | 8/9/2014 | 17/6/2026 | Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (6.8) | 2.0% | — | Amos Benari Rbovirt | 17/4/2014 | 17/6/2026 | The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors. | |
| Modificada | Baja (3.6) | 0.34% | — | Ovirt Sanlock | 20/12/2012 | 16/6/2026 | The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations. | |
| Modificada | Media (5) | 1.1% | — | OvirtOvirt-engine-cliOvirt-engine-sdk 3.1.0.5 | 31/8/2012 | 16/6/2026 | The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows remote attackers to spoof a server via a man-in-the-middle (MITM) attack. |