Known vulnerabilities in SUSE OpenStack Cloud 8 - page 2

Vendor: SUSE
Version: 8
Software CPE: cpe:2.3:o:suse:suse_openstack_cloud:*:*:*:*:*:*:*:*
Total vulnerabilities: 802
Public exploits: 42
Known exploited (KEV): 21
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting SUSE OpenStack Cloud version 8 SUSE OpenStack Cloud 8 is affected by 802 vulnerabilities: 12 critical, 229 high, 277 medium, 284 low Critical High Medium Low

Vulnerabilities (802)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75486 - Improper input validation
CVE-2023-29007
CWE-20 Low
Public exploit available
No
- 25.04.2023 SB2023042553
SB2023042610
SB2023042629
and 48 more
#VU75485 - Insufficient Verification of Data Authenticity
CVE-2023-25815
CWE-345 Low
No
No
- 25.04.2023 SB2023042553
SB2023042610
SB2023042638
and 40 more
#VU72330 - Resource exhaustion
CVE-2023-24580
CWE-400 Medium
No
No
- 16.02.2023 SB2023021645
SB2023021648
SB2023031032
and 15 more
#VU72246 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-22490
CWE-59 Low
No
No
- 15.02.2023 SB2023021529
SB2023021528
SB2023021533
and 31 more
#VU72245 - Improper Link Resolution Before File Access ('Link Following')
CVE-2023-23946
CWE-59 Medium
No
No
- 15.02.2023 SB2023021529
SB2023021528
SB2023021533
and 28 more
#VU71714 - External Control of File Name or Path
CVE-2022-47951
CWE-73 Medium
No
No
- 31.01.2023 SB2023013129
SB2023013130
SB2023013131
and 15 more
#VU71379 - Incorrect Regular Expression
CVE-2022-40897
CWE-185 Medium
No
No
- 20.01.2023 SB2023012008
SB2023012015
SB2023012016
and 99 more
#VU71239 - Integer overflow
CVE-2022-23521
CWE-190 High
No
No
- 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 52 more
#VU71238 - Heap-based Buffer Overflow
CVE-2022-41903
CWE-122 High
No
No
- 17.01.2023 SB2023011739
SB2023011741
SB2023011804
and 51 more
#VU71237 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-47950
CWE-611 Medium
No
No
- 17.01.2023 SB2023011738
SB2023012566
SB2023020941
and 5 more
#VU68855 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-39348
CWE-79 Low
No
No
- 31.10.2022 SB2022103137
SB20221115106
SB2022111743
and 12 more
#VU68518 - Heap-based Buffer Overflow
CVE-2022-39260
CWE-122 High
No
No
- 19.10.2022 SB2022101995
SB2022101996
SB2022101997
and 23 more
#VU68517 - Improper input validation
CVE-2022-39253
CWE-20 Low
Public exploit available
No
- 19.10.2022 SB2022101995
SB2022101996
SB2022101997
and 41 more
#VU67757 - Improper Access Control
CVE-2022-3100
CWE-284 Medium
No
No
- 29.09.2022 SB2022092961
SB2022092965
SB2022100505
and 3 more
#VU67555 - Incorrect Regular Expression
CVE-2022-40023
CWE-185 Medium
No
No
- 21.09.2022 SB2022092139
SB2022092141
SB2022102426
and 20 more
#VU66201 - Security Features
CVE-2022-2255
CWE-254 Medium
No
No
- 09.08.2022 SB2022080904
SB2022080914
SB2022111643
and 6 more
#VU61488 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24761
CWE-444 Medium
No
No
- 21.03.2022 SB2022032107
SB2022040525
SB2022040622
and 12 more
#VU26355 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-10108
CWE-444 Medium
No
No
- 24.03.2020 SB2020031234
SB2020032419
SB2020043012
and 11 more
#VU24218 - Improper input validation
CVE-2019-11287
CWE-20 Medium
No
No
- 13.01.2020 SB2019112307
SB2020011311
SB2021062428
and 5 more
#VU31043 - Improper input validation
CVE-2019-12387
CWE-20 Medium
No
No
- 10.06.2019 SB2019061006
SB2019072125
SB2019072129
and 4 more


Showing elements 21 - 40 out of 802