Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.28% | — | Openstack Oslo.messagingAI | 4/6/2026 | 27/8/2026 | An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expected broker hostname… | |
| Modificada | Media (4.9) | 1.7% | — | Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux | 29/8/2022 | 17/6/2026 | A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. | |
| Modificada | Crítica (9.3) | 0.35% | — | Google Guest-osloginOpensuse Leap | 22/6/2020 | 17/6/2026 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it… | |
| Modificada | Crítica (9.3) | 0.31% | — | Google Guest-osloginOpensuse Leap | 22/6/2020 | 17/6/2026 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacker with this role is able to run docker and mount the host OS.… | |
| Modificada | Alta (7.3) | 0.32% | — | Google Guest-osloginOpensuse Leap | 22/6/2020 | 17/6/2026 | A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal.… | |
| Modificada | Media (5.5) | 0.45% | — | Openstack Oslo.middlewareCanonical Ubuntu Linux | 8/5/2018 | 17/6/2026 | python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for… | |
| Modificada | Media (5) | 2.8% | — | Redhat OpenstackCanonical Ubuntu LinuxOpenstack NeutronOpenstack Oslo+2 | 19/8/2014 | 17/6/2026 | The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request). | |
| Modificada | Media (4.3) | 1.9% | — | Openstack OsloRedhat Openstack | 2/2/2014 | 17/6/2026 | The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (7.5) | 8.3% | — | Kynoslogic Cruiseworks | 27/10/2006 | 16/6/2026 | Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter. | |
| Modificada | Media (5) | 2.2% | — | Kynoslogic Cruiseworks | 27/10/2006 | 16/6/2026 | Directory traversal vulnerability in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to read arbitrary files via a .. (dot dot) in the doc parameter. |