openstack records
292 published records for vendor openstack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 94.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42
- CWE-264 Permissions, Privileges, and Access Controls37
- CWE-399 Resource Management Errors22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-20 Improper Input Validation13
- CWE-863 Incorrect Authorization12
The weakness classes this vendor ships most often: where to look.
CWEAll records
292 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2017-18017No exploit | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Critical9.8 | — | 52.8% | Jan 3, 2018 |
42Plan | CVE-2017-16613No exploit | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.openstack · swauth · CWE-287 | Critical9.8 | — | 8.4% | Nov 21, 2017 |
41Plan | CVE-2012-4406No exploit | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadataopenstack · swift · CWE-502 | Critical9.8 | — | 6.6% | Oct 22, 2012 |
40Plan | CVE-2020-26943No exploit | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.openstack · blazar-dashboard | Critical9.9 | — | 3.3% | Oct 16, 2020 |
40Plan | CVE-2016-4972No exploit | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)openstack · mitaka-murano · CWE-20 | Critical9.8 | — | 3.2% | Sep 26, 2016 |
40Plan | CVE-2017-7214No exploit | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Critical9.8 | — | 2.3% | Mar 21, 2017 |
40Plan | CVE-2013-2166No exploit | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypassopenstack · python-keystoneclient · CWE-326 | Critical9.8 | — | 2.1% | Dec 10, 2019 |
40Plan | CVE-2013-2167No exploit | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypassopenstack · python-keystoneclient · CWE-345 | Critical9.8 | — | 2.0% | Dec 10, 2019 |
40Plan | CVE-2016-7404No exploit | OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.openstack · magnum · CWE-200 | Critical9.8 | — | 1.9% | Jun 21, 2019 |
39Monitor | CVE-2024-28718No exploit | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.openstack · magnum · CWE-367 | Critical9.8 | — | 1.1% | Apr 12, 2024 |
39Monitor | CVE-2026-31072No exploit | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCCWE-502 | Critical9.8 | — | 1.0% | May 19, 2026 |
39Monitor | CVE-2026-41283No exploit | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.openstack · mistral · CWE-863 | Critical9.9 | — | 0.9% | Jun 4, 2026 |
39Monitor | CVE-2026-22797No exploit | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1openstack · keystonemiddleware · CWE-290 | Critical9.9 | — | 0.7% | Jan 19, 2026 |
37Monitor | CVE-2015-8914No exploit | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofinopenstack · neutron · CWE-254 | Critical9.1 | — | 4.3% | Jun 17, 2016 |
37Monitor | CVE-2014-0187No exploit | The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to byopenstack · neutron · CWE-264 | Critical9.0 | — | 2.9% | Apr 28, 2014 |
37Monitor | CVE-2019-15753No exploit | In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatopenstack · os-vif · CWE-770 | Critical9.1 | — | 2.6% | Aug 28, 2019 |
37Monitor | CVE-2019-10141No exploit | A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.openstack · ironic-inspector · CWE-89 | Critical9.1 | — | 2.5% | Jul 30, 2019 |
36Monitor | CVE-2020-12691No exploit | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-863 | High8.8 | — | 4.9% | May 6, 2020 |
36Monitor | CVE-2020-12690No exploit | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-613 | High8.8 | — | 1.9% | May 6, 2020 |
36Monitor | CVE-2019-19687No exploit | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.openstack · keystone · CWE-522 | High8.8 | — | 1.8% | Dec 9, 2019 |
36Monitor | CVE-2021-38598No exploit | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtabopenstack · neutron · CWE-290 | Critical9.1 | — | 1.2% | Aug 23, 2021 |
36Monitor | CVE-2026-28370No exploit | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger codopenstack · vitrage · CWE-95 | Critical9.1 | — | 0.8% | Feb 27, 2026 |
35Monitor | CVE-2017-17051No exploit | An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.openstack · nova · CWE-400 | High8.6 | — | 2.0% | Dec 5, 2017 |
35Monitor | CVE-2020-12689No exploit | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-269 | High8.8 | — | 1.6% | May 6, 2020 |
35Monitor | CVE-2018-10898No exploit | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.openstack · tripleo heat templates · CWE-798 | High8.8 | — | 0.9% | Jul 30, 2018 |
- CVE-2017-1801755Plan
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
CriticalCVSS 9.8No exploitEPSS 53%linux · linux kernelJan 3, 2018
- CVE-2017-1661342Plan
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.
CriticalCVSS 9.8No exploitEPSS 8%openstack · swauthNov 21, 2017
- CVE-2012-440641Plan
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata
CriticalCVSS 9.8No exploitEPSS 7%openstack · swiftOct 22, 2012
- CVE-2020-2694340Plan
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.
CriticalCVSS 9.9No exploitEPSS 3%openstack · blazar-dashboardOct 16, 2020
- CVE-2016-497240Plan
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)
CriticalCVSS 9.8No exploitEPSS 3%openstack · mitaka-muranoSep 26, 2016
- CVE-2017-721440Plan
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
CriticalCVSS 9.8No exploitEPSS 2%openstack · novaMar 21, 2017
- CVE-2013-216640Plan
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
CriticalCVSS 9.8No exploitEPSS 2%openstack · python-keystoneclientDec 10, 2019
- CVE-2013-216740Plan
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
CriticalCVSS 9.8No exploitEPSS 2%openstack · python-keystoneclientDec 10, 2019
- CVE-2016-740440Plan
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.
CriticalCVSS 9.8No exploitEPSS 2%openstack · magnumJun 21, 2019
- CVE-2024-2871839Monitor
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.
CriticalCVSS 9.8No exploitEPSS 1%openstack · magnumApr 12, 2024
- CVE-2026-3107239Monitor
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC
CriticalCVSS 9.8No exploitEPSS 1%May 19, 2026
- CVE-2026-4128339Monitor
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.
CriticalCVSS 9.9No exploitEPSS 1%openstack · mistralJun 4, 2026
- CVE-2026-2279739Monitor
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1
CriticalCVSS 9.9No exploitEPSS 1%openstack · keystonemiddlewareJan 19, 2026
- CVE-2015-891437Monitor
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofin
CriticalCVSS 9.1No exploitEPSS 4%openstack · neutronJun 17, 2016
- CVE-2014-018737Monitor
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to by
CriticalCVSS 9.0No exploitEPSS 3%openstack · neutronApr 28, 2014
- CVE-2019-1575337Monitor
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligat
CriticalCVSS 9.1No exploitEPSS 3%openstack · os-vifAug 28, 2019
- CVE-2019-1014137Monitor
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.
CriticalCVSS 9.1No exploitEPSS 2%openstack · ironic-inspectorJul 30, 2019
- CVE-2020-1269136Monitor
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
HighCVSS 8.8No exploitEPSS 5%openstack · keystoneMay 6, 2020
- CVE-2020-1269036Monitor
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
HighCVSS 8.8No exploitEPSS 2%openstack · keystoneMay 6, 2020
- CVE-2019-1968736Monitor
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.
HighCVSS 8.8No exploitEPSS 2%openstack · keystoneDec 9, 2019
- CVE-2021-3859836Monitor
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab
CriticalCVSS 9.1No exploitEPSS 1%openstack · neutronAug 23, 2021
- CVE-2026-2837036Monitor
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger cod
CriticalCVSS 9.1No exploitEPSS 1%openstack · vitrageFeb 27, 2026
- CVE-2017-1705135Monitor
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.
HighCVSS 8.6No exploitEPSS 2%openstack · novaDec 5, 2017
- CVE-2020-1268935Monitor
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
HighCVSS 8.8No exploitEPSS 2%openstack · keystoneMay 6, 2020
- CVE-2018-1089835Monitor
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.
HighCVSS 8.8No exploitEPSS 1%openstack · tripleo heat templatesJul 30, 2018