Openstack

Vendor:

First CVE: Jul 31, 2013 · Active for 12 years

213
Total CVEs
More Total CVEs than 99% of tracked products
19.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
May 12, 2023
1,169 days ago

CVE Severity & Scoring

Openstack213 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local54 (25.4%)
Network118 (55.4%)
Unknown37 (17.4%)
Physical0 (0.0%)
Adjacent Network4 (1.9%)
Attack Complexity
Low143 (67.1%)
High33 (15.5%)
Unknown37 (17.4%)
User Interaction
None158 (74.2%)
Unknown37 (17.4%)
Required18 (8.5%)
Privileges Required
Low80 (37.6%)
High25 (11.7%)
None71 (33.3%)
Unknown37 (17.4%)

Top CVEs

Signals from CVEs in this product scope (213 CVEs).

213 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that ca
Mar 5, 20187.586NOYES
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.
Sep 20, 20169.878NOYES
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overfl
Jun 17, 20189.873NOYES
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to
Aug 7, 20207.568NONO
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea
Aug 13, 20197.565NONO
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori
May 22, 20185.565NOYES
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to
Jul 31, 20136.045NOYES
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil
Jul 31, 20136.043NOYES
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p
May 13, 20157.742NOYES

Exploit Exposure

Signals from CVEs in this product scope (213 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
1.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
3.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (213 CVEs).

Media Mentions

Signals from CVEs in this product scope (213 CVEs).

Top CNAs Publishing CVEs For Openstack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9417.18.4%03
8407.27.4%03
7.0437.15.4%03
6.0407.34.1%03
5.0326.95.1%03
4.0185.83.1%01
3.0196.54.2%02
2.117.51.0%00
2.015.50.3%00
1724.30.4%00
16.285.60.7%00
16.1115.99.0%00
15106.81.9%00
14157.316.7%00
13606.74.8%02
12376.26.2%02
11246.85.8%02
10687.05.6%03
115.50.4%00