Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.39% | — | Redhat Openstack Platform | 21/8/2024 | 17/6/2026 | A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack. | |
| Modificada | Media (5) | 0.39% | — | Openstack HeatRedhat Openstack Platform | 2/8/2024 | 17/6/2026 | An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied. | |
| Modificada | Media (6.5) | 0.95% | — | Openstack Nova | 24/7/2024 | 17/6/2026 | In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the… | |
| Modificada | Media (6.5) | 0.83% | — | Openstack CinderOpenstack GlanceOpenstack Nova | 5/7/2024 | 17/6/2026 | An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that… | |
| Aplazada | Media (5.5) | 0.20% | — | Redhat Openstack PlatformAIOpenstackAI | 14/5/2024 | 17/6/2026 | An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs. | |
| Aplazada | Alta (7.5) | 0.79% | — | Redhat Openstack PlatformAIRedhat Enterprise LinuxAIGolang X NETAI | 8/5/2024 | 17/6/2026 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux… | |
| Aplazada | Alta (7.5) | 0.77% | — | Redhat Openstack PlatformAIRedhat Enterprise LinuxAI | 8/5/2024 | 17/6/2026 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated… | |
| Aplazada | Alta (7.5) | 0.77% | — | Golang NETAIRedhat Openstack PlatformAIRedhat Enterprise LinuxAI | 8/5/2024 | 17/6/2026 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated… | |
| Aplazada | Alta (7.5) | 1.4% | — | Openstack StorletsAI | 30/4/2024 | 17/6/2026 | An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component. | |
| Aplazada | Media (4.9) | 0.89% | — | Openstack StorletsAI | 22/4/2024 | 17/6/2026 | An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component. | |
| Aplazada | Media (4.7) | 0.21% | — | Openstack IronicAIOpenstack Ironic InspectorAI | 17/4/2024 | 17/6/2026 | Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, 1) HTTP basic credentials are validated on the HTTPD side in a separate container, not in the Ironic service itself and 2) Ironic listens… | |
| Analizada | Crítica (9.8) | 1.1% | — | Openstack Magnum | 12/4/2024 | 17/6/2026 | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component. | |
| Modificada | Media (6.5) | 0.75% | — | Openstack MuranoOpenstack Yaql | 18/3/2024 | 17/6/2026 | In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information. | |
| Modificada | Media (5.5) | 0.20% | — | Redhat Openstack Platform | 15/3/2024 | 17/6/2026 | An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information. | |
| Modificada | Media (5.5) | 0.23% | — | Openstack Glance-store | 1/2/2024 | 17/6/2026 | A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled. | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.5) | 0.80% | — | Redhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR PowerRedhat Openshift Container Platform IBM Z Systems+1 | 1/11/2023 | 17/6/2026 | A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5) | 0.48% | — | Openstack BarbicanRedhat Openstack Platform | 24/9/2023 | 17/6/2026 | A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain… | |
| Modificada | Media (5.5) | 0.19% | — | Openstack BarbicanRedhat Openstack Platform | 24/9/2023 | 17/6/2026 | A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. | |
| Modificada | Media (5) | 0.71% | — | Openstack HeatRedhat Openstack Platform | 24/9/2023 | 17/6/2026 | An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Openstack Platform | 20/9/2023 | 17/6/2026 | An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials. | |
| Modificada | Alta (7.5) | 0.29% | — | Redhat Openstack Platform | 15/9/2023 | 17/6/2026 | A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Media (6.1) | 0.80% | — | Openstack Horizon | 22/8/2023 | 17/6/2026 | Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. |