Openstack
Vendor:
First CVE: Jul 31, 2013 · Active for 12 years
213
Total CVEs
More Total CVEs than 99% of tracked products
19.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openstack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
May 12, 2023
1,169 days ago
CVE Severity & Scoring
Openstack213 CVEs
54%
31%
10%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local54 (25.4%)
Network118 (55.4%)
Unknown37 (17.4%)
Physical0 (0.0%)
Adjacent Network4 (1.9%)
Attack Complexity
Low143 (67.1%)
High33 (15.5%)
Unknown37 (17.4%)
User Interaction
None158 (74.2%)
Unknown37 (17.4%)
Required18 (8.5%)
Privileges Required
Low80 (37.6%)
High25 (11.7%)
None71 (33.3%)
Unknown37 (17.4%)
Top CVEs
Signals from CVEs in this product scope (213 CVEs).
213 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000115HIGH Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that ca | Mar 5, 2018 | 7.5 | 86 | NO | YES |
CVE-2016-6662CRITICAL Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5. | Sep 20, 2016 | 9.8 | 78 | NO | YES |
CVE-2018-11218CRITICAL Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overfl | Jun 17, 2018 | 9.8 | 73 | NO | YES |
CVE-2020-9490HIGH Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to | Aug 7, 2020 | 7.5 | 68 | NO | NO |
CVE-2019-9515HIGH Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF | Aug 13, 2019 | 7.5 | 66 | NO | NO |
CVE-2019-9514HIGH Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea | Aug 13, 2019 | 7.5 | 65 | NO | NO |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2013-2121MEDIUM Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to | Jul 31, 2013 | 6.0 | 45 | NO | YES |
CVE-2013-2113MEDIUM The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil | Jul 31, 2013 | 6.0 | 43 | NO | YES |
CVE-2015-3456HIGH The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p | May 13, 2015 | 7.7 | 42 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (213 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
1.9% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
3.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (213 CVEs).
Media Mentions
Signals from CVEs in this product scope (213 CVEs).
Top CNAs Publishing CVEs For Openstack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 41 | 7.1 | 8.4% | 0 | 3 |
| 8 | 40 | 7.2 | 7.4% | 0 | 3 |
| 7.0 | 43 | 7.1 | 5.4% | 0 | 3 |
| 6.0 | 40 | 7.3 | 4.1% | 0 | 3 |
| 5.0 | 32 | 6.9 | 5.1% | 0 | 3 |
| 4.0 | 18 | 5.8 | 3.1% | 0 | 1 |
| 3.0 | 19 | 6.5 | 4.2% | 0 | 2 |
| 2.1 | 1 | 7.5 | 1.0% | 0 | 0 |
| 2.0 | 1 | 5.5 | 0.3% | 0 | 0 |
| 17 | 2 | 4.3 | 0.4% | 0 | 0 |
| 16.2 | 8 | 5.6 | 0.7% | 0 | 0 |
| 16.1 | 11 | 5.9 | 9.0% | 0 | 0 |
| 15 | 10 | 6.8 | 1.9% | 0 | 0 |
| 14 | 15 | 7.3 | 16.7% | 0 | 0 |
| 13 | 60 | 6.7 | 4.8% | 0 | 2 |
| 12 | 37 | 6.2 | 6.2% | 0 | 2 |
| 11 | 24 | 6.8 | 5.8% | 0 | 2 |
| 10 | 68 | 7.0 | 5.6% | 0 | 3 |
| 1 | 1 | 5.5 | 0.4% | 0 | 0 |