Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.6% | — | Novastor Novabackup Datacenter | 13/4/2017 | 17/6/2026 | The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors. | |
| Modificada | Alta (7.5) | 2.9% | — | Canonical Ubuntu LinuxOpenstack Nova-lxd | 12/4/2017 | 17/6/2026 | OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Openstack Nova | 21/3/2017 | 17/6/2026 | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens. | |
| Modificada | Alta (7.2) | 1.2% | — | Sauter-controls Novaweb WEB HMI | 13/2/2017 | 17/6/2026 | An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user. | |
| Modificada | Alta (7.5) | 3.1% | — | Openstack CinderOpenstack GlanceOpenstack Nova | 7/10/2016 | 17/6/2026 | The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image. | |
| Modificada | Media (6.5) | 2.3% | — | Openstack Compute (nova) | 27/9/2016 | 17/6/2026 | OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression. | |
| Modificada | Media (5.3) | 2.1% | — | Openstack Nova | 12/4/2016 | 17/6/2026 | The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk. | |
| Modificada | Media (5.9) | 2.2% | — | Openstack Nova | 15/1/2016 | 17/6/2026 | The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or… | |
| Modificada | Baja (3.5) | 1.8% | — | Openstack Nova | 12/1/2016 | 17/6/2026 | OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot. | |
| Modificada | Media (5) | 3.7% | — | Openstack Nova | 29/10/2015 | 17/6/2026 | OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made. | |
| Modificada | Media (6.8) | 3.4% | — | Openstack Nova | 26/10/2015 | 17/6/2026 | OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. | |
| Modificada | Media (6.8) | 3.5% | — | Openstack Nova | 8/9/2015 | 17/6/2026 | OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance. | |
| Modificada | Alta (7.5) | 2.0% | — | Novalnet Payment Module Ubercart- | 18/8/2015 | 17/6/2026 | SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 1.3% | — | RLE Nova-wind Turbine HMI Firmware | 13/6/2015 | 17/6/2026 | RLE Nova-Wind Turbine HMI devices store cleartext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.1) | 1.1% | — | Openstack Nova | 1/4/2015 | 17/6/2026 | OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage. | |
| Modificada | Media (4) | 2.0% | — | Redhat OpenstackOpenstack Nova | 31/10/2014 | 17/6/2026 | The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state. | |
| Modificada | Media (4) | 2.8% | — | Openstack NovaRedhat Openstack | 31/10/2014 | 17/6/2026 | OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API request. | |
| Modificada | Media (5.4) | 0.27% | — | Nova921 Nova 92.1 FM | 20/10/2014 | 17/6/2026 | The Nova 92.1 FM (aka com.wNova921FM) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 2.0% | — | Openstack Nova | 15/10/2014 | 17/6/2026 | Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances. | |
| Modificada | Baja (2.1) | 0.53% | — | Openstack CinderOpenstack NovaOpenstack TroveRedhat Openstack | 8/10/2014 | 17/6/2026 | The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log. | |
| Modificada | Baja (2.1) | 0.49% | — | Openstack CinderOpenstack NovaOpenstack TroveRedhat Openstack+1 | 8/10/2014 | 17/6/2026 | The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log. | |
| Modificada | Baja (2.7) | 1.7% | — | Openstack Nova | 6/10/2014 | 17/6/2026 | The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability… | |
| Modificada | Media (5.4) | 0.27% | — | Popoinnovation Slotmachine | 25/9/2014 | 17/6/2026 | The SlotMachine (aka com.popoinnovation.SlotMachine) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Sportinginnovations Utah Jazz | 25/9/2014 | 17/6/2026 | The Sporting Club Uphoria (aka com.sportinginnovations.skc) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Sportinginnovations Utah Jazz | 25/9/2014 | 17/6/2026 | The Utah Jazz (aka com.sportinginnovations.jazz) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |