Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ovirt

First CVE: Aug 31, 2012Active for: 14 yearsTotal CVEs: 34
45.8
VTI Score
High

oVirt is a virtualization management platform deployed primarily in enterprise data centers, with vulnerability exposure spanning its core engine, hypervisor node, and host agent components. The vendor's vulnerability profile reflects the structural challenges of managing complex distributed infrastructure: a moderate share of disclosures reach serious severity, and the recurring weakness classes concentrate on sensitive-data exposure, credential handling, input validation in web interfaces, and privilege-management boundaries that are characteristic of large management platforms with broad system-level access. Defenders should treat oVirt deployments as high-value targets and prioritize patches affecting the engine and authentication layers, since these components control cluster-wide operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
2.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Ovirt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2012
13 years ago
Most Recent CVE
Sep 26, 2024
665 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0847HIGH
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker
Mar 10, 20227.898YESYES
CVE-2022-0435HIGH
A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is
Mar 25, 20228.867NONO
CVE-2018-1072CRITICAL
ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the options "--provision*db", the databas
Jun 26, 20189.830NONO
CVE-2018-1117CRITICAL
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/CloudForms' playbook inadvertently
Jun 20, 20189.829NONO
CVE-2019-3879HIGH
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be perfo
Mar 25, 20198.126NONO
CVE-2013-0293HIGH
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
Dec 10, 20197.825NONO
CVE-2012-4480HIGH
mom creates world-writable pid files in /var/run
Dec 2, 20197.824NONO
CVE-2019-10139HIGH
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleVarFileXXXXXX.var` which contains the ad
May 17, 20197.824NONO
CVE-2018-1000018HIGH
An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.
Jan 24, 20187.824NONO
CVE-2012-5518HIGH
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
Nov 25, 20197.523NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
50%
41%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (38.2%)
Network16 (47.1%)
Unknown5 (14.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (76.5%)
High3 (8.8%)
Unknown5 (14.7%)
User Interaction
None25 (73.5%)
Unknown5 (14.7%)
Required4 (11.8%)
Privileges Required
Low16 (47.1%)
High4 (11.8%)
None9 (26.5%)
Unknown5 (14.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
1 CVE
2.9% of CVEs· 99th percentile
Metasploit
1 CVE
2.9% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ovirt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ovirt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ovirt's Products

View all 2 CNAs →

Top CWEs