Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Redhat Openstack Platform | 25/7/2023 | 17/6/2026 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests,… | |
| Modificada | Alta (7.5) | 1.6% | — | QemuRedhat Openstack PlatformRedhat Enterprise LinuxFedoraproject Fedora | 11/7/2023 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat Openstack | 12/5/2023 | 17/6/2026 | A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to confidentiality. | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important… | |
| Modificada | Media (5.5) | 0.20% | — | Openstack Tripleo AnsibleRedhat OpenstackRedhat Openstack FOR IBM Power | 23/3/2023 | 17/6/2026 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration… | |
| Modificada | Baja (2.8) | 0.33% | — | Openstack GlanceRedhat Openstack | 6/3/2023 | 17/6/2026 | A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images. | |
| Modificada | Media (6.5) | 1.1% | — | Openstack NeutronRedhat Openstack Platform | 6/3/2023 | 17/6/2026 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests,… | |
| Modificada | Media (5.7) | 1.0% | — | Openstack CinderOpenstack GlanceOpenstack NovaDebian Linux | 26/1/2023 | 17/6/2026 | An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user… | |
| Modificada | Media (6.5) | 1.0% | — | Openstack SwiftDebian Linux | 18/1/2023 | 17/6/2026 | An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both… | |
| Modificada | Media (5.9) | 0.44% | — | Openstack BarbicanRedhat OpenstackRedhat Openstack FOR IBM PowerRedhat Openstack Platform | 18/1/2023 | 17/6/2026 | A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. | |
| Modificada | Alta (8.8) | 0.60% | — | Redhat Openstack | 21/12/2022 | 17/6/2026 | A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges. | |
| Modificada | Alta (7.8) | 0.22% | — | Openstack Kolla | 21/12/2022 | 17/6/2026 | A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges. | |
| Modificada | Media (5.5) | 0.30% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 29/9/2022 | 17/6/2026 | Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu… | |
| Modificada | Media (6.2) | 0.33% | — | QemuFedoraproject FedoraRedhat VirtualizationRedhat Enterprise Linux Desktop+6 | 29/9/2022 | 17/6/2026 | Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine. | |
| Modificada | Alta (8.6) | 1.0% | — | QemuRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 29/9/2022 | 17/6/2026 | QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process. | |
| Modificada | Alta (8.1) | 1.3% | — | Openstack BarbicanRedhat Openstack Platform | 6/9/2022 | 17/6/2026 | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of… | |
| Modificada | Media (6.6) | 0.72% | — | Openstack KeystoneRedhat Openstack PlatformRedhat QuayRedhat Storage | 1/9/2022 | 17/6/2026 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected. | |
| Modificada | Media (4.9) | 1.3% | — | Openstack BarbicanRedhat Openstack Platform | 1/9/2022 | 17/6/2026 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service. | |
| Modificada | Alta (8.6) | 2.2% | — | Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+4 | 31/8/2022 | 17/6/2026 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | |
| Modificada | Media (4.9) | 1.7% | — | Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux | 29/8/2022 | 17/6/2026 | A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. | |
| Modificada | Media (5.5) | 0.25% | — | Openstack Tripleo Heat Templates | 26/8/2022 | 17/6/2026 | A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. | |
| Modificada | Alta (7.4) | 1.7% | — | Openstack KeystoneDebian LinuxRedhat Openstack Platform | 26/8/2022 | 17/6/2026 | A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+3 | 25/8/2022 | 17/6/2026 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. | |
| Modificada | Baja (3.2) | 0.39% | — | QemuFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Openstack Platform+1 | 17/8/2022 | 17/6/2026 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service. |