Vulnerabilities
Summary — last 7 days
New vulnerabilities2,757▲ 47 vs. last week
Critical / high1,482▲ 372 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Low (2.1) | 2.1% | — | Apache Libcloud | 1/7/2014 | 6/17/2026 | Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM. | |
| Modified | Medium (5.9) | 1.2% | — | Apache Libcloud | 11/4/2012 | 6/16/2026 | Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. | |
| Modified | Medium (4.3) | 1.4% | — | Apache Libcloud | 9/12/2011 | 6/16/2026 | libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. |