Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.31%—Openstack Nova3/8/202217/6/2026
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to macvtap, an authenticated user may cause the compute service to fail…
ModificadaMedia (4.3)0.56%—Jenkins Openstack Heat27/7/202217/6/2026
Jenkins Openstack Heat Plugin 1.5 and earlier does not perform permission checks in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
ModificadaMedia (4.3)0.57%—Jenkins Openstack Heat27/7/202217/6/2026
A missing permission check in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.
ModificadaMedia (6.5)0.44%—Jenkins Openstack Heat27/7/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Openstack Heat Plugin 1.5 and earlier allows attackers to connect to an attacker-specified URL.
ModificadaMedia (6.5)0.54%—Redhat Openstack22/7/202217/6/2026
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
AnalizadaMedia (5.3)0.90%—Redhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Wildfly10/5/202217/6/2026
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field is used by the…
ModificadaAlta (7.8)0.58%—Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+1527/4/202217/6/2026
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
ModificadaMedia (4.3)0.79%—Openstack Tripleo Heat TemplatesRedhat Openstack23/3/202217/6/2026
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid…
ModificadaMedia (6.5)0.37%—QemuFedoraproject FedoraRedhat Openstack PlatformRedhat Enterprise Linux+416/3/202217/6/2026
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The…
ModificadaAlta (8.8)0.66%—Linux KernelFedoraproject FedoraRedhat Software CollectionsRedhat Openstack+224/3/202217/6/2026
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable…
ModificadaMedia (5.5)0.39%—Redhat Ansible Automation Platform Early AccessRedhat Ansible EngineRedhat OpenstackRedhat Virtualization+53/3/202217/6/2026
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
ModificadaMedia (6.1)27%—Openstack NovaRedhat Openstack Platform2/3/202217/6/2026
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
ModificadaMedia (6.5)0.34%—QemuRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little Endian+618/2/202217/6/2026
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
ModificadaAlta (8.1)1.6%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2118/2/202217/6/2026
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
ModificadaMedia (5.9)1.8%—SambaDebian LinuxFedoraproject FedoraRedhat Codeready Linux Builder+2018/2/202217/6/2026
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
ModificadaMedia (6.5)1.8%—Openstack Neutron8/9/202117/6/2026
An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory, resulting in API performance degradation or…
ModificadaMedia (6.5)1.8%—Openstack NeutronDebian Linux31/8/202117/6/2026
An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.
ModificadaCrítica (9.1)1.2%—Openstack Neutron23/8/202117/6/2026
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the…
ModificadaAlta (7.5)2.5%—Openstack Keystone6/8/202117/6/2026
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both…
ModificadaMedia (6.5)0.22%—Redhat Openstack-selinuxRedhat Openstack Platform7/6/202117/6/2026
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With access to the dbus, the attacker could…
ModificadaMedia (6.5)0.31%—QemuDebian LinuxFedoraproject FedoraRedhat Openstack Platform+12/6/202117/6/2026
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.
ModificadaMedia (4.3)0.80%—Openstack Swift2/6/202117/6/2026
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
ModificadaAlta (7.1)1.0%—Openstack NeutronRedhat Openstack Platform28/5/202117/6/2026
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly…
ModificadaAlta (7.5)1.00%—Redhat Openstack6/5/202117/6/2026
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
ModificadaAlta (7.5)2.8%—PygmentsRedhat Openshift Container PlatformRedhat Openstack PlatformRedhat Software Collections+323/3/202117/6/2026
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.