Vulnerabilities

Summary — last 7 days

New vulnerabilities2,757▲ 47 vs. last week
Critical / high1,482▲ 372 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedLow (2.1)2.1%—Apache Libcloud1/7/20146/17/2026
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
ModifiedMedium (5.9)1.2%—Apache Libcloud11/4/20126/16/2026
Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
ModifiedMedium (4.3)1.4%—Apache Libcloud9/12/20116/16/2026
libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack.