Nova
Vendor:
First CVE: Dec 23, 2011 · Active for 14 years
40
Total CVEs
More Total CVEs than 97% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nova over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2011
14 years ago
Most Recent CVE
Jun 16, 2026
38 days ago
CVE Severity & Scoring
Nova40 CVEs
20%
60%
18%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (7.5%)
Network18 (45.0%)
Unknown19 (47.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (40.0%)
High5 (12.5%)
Unknown19 (47.5%)
User Interaction
None19 (47.5%)
Unknown19 (47.5%)
Required2 (5.0%)
Privileges Required
Low13 (32.5%)
High0 (0.0%)
None8 (20.0%)
Unknown19 (47.5%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3654MEDIUM A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. | Mar 2, 2022 | 6.1 | 46 | NO | YES |
CVE-2026-46448HIGH In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation. | Jun 16, 2026 | 8.5 | 33 | NO | NO |
CVE-2017-7214CRITICAL An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearin | Mar 21, 2017 | 9.8 | 31 | NO | NO |
CVE-2026-24708HIGH An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering | Feb 18, 2026 | 8.2 | 30 | NO | NO |
CVE-2017-17051HIGH An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked r | Dec 5, 2017 | 8.6 | 28 | NO | NO |
CVE-2011-3147HIGH Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem. | Apr 22, 2019 | 8.6 | 27 | NO | NO |
CVE-2020-17376HIGH An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that h | Aug 26, 2020 | 8.3 | 26 | NO | NO |
CVE-2024-32498MEDIUM An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplyi | Jul 5, 2024 | 6.5 | 23 | NO | NO |
CVE-2019-14433MEDIUM An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to | Aug 9, 2019 | 6.5 | 23 | NO | NO |
CVE-2017-16239MEDIUM In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypa | Nov 14, 2017 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Nova
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| folsom | 1 | 3.5 | 1.5% | 0 | 0 |
| 21.0.0 | 1 | 8.3 | 1.7% | 0 | 0 |
| 2015.1.0 | 1 | 5.1 | 1.1% | 0 | 0 |
| 2014.2.0 | 1 | 4.3 | 1.9% | 0 | 0 |
| 2014.2 | 1 | 6.5 | 2.0% | 0 | 0 |
| 2014.1 | 1 | 4.0 | 2.0% | 0 | 0 |
| 2013.2 | 1 | 6.0 | 1.8% | 0 | 0 |
| 2012.1 | 2 | 4.2 | 1.7% | 0 | 0 |
| 2011.3 | 2 | 4.2 | 1.6% | 0 | 0 |
| 16.0.3 | 1 | 8.6 | 2.0% | 0 | 0 |
| 16.0.2 | 1 | 6.5 | 1.4% | 0 | 0 |
| 16.0.1 | 1 | 6.5 | 1.4% | 0 | 0 |
| 16.0.0 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.7 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.6 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.5 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.4 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.3 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.2 | 1 | 6.5 | 1.4% | 0 | 0 |
| 15.0.1 | 2 | 8.2 | 1.8% | 0 | 0 |