Opennebula

Opennebula

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.5%
  • Veröffentlicht 01.09.2026 10:49:22
  • Zuletzt bearbeitet 01.09.2026 20:50:58

A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belongi...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 29.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 20:09:13

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 29.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 20:09:05

A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 29.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 20:08:58

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.

Exploit
  • EPSS 0.19%
  • Veröffentlicht 29.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 20:01:08

A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.

  • EPSS 0.34%
  • Veröffentlicht 02.08.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSON Web Token...

  • EPSS 1.58%
  • Veröffentlicht 28.10.2022 16:15:16
  • Zuletzt bearbeitet 21.11.2024 07:14:58

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

  • EPSS 0.52%
  • Veröffentlicht 28.10.2022 16:15:16
  • Zuletzt bearbeitet 21.11.2024 07:14:58

Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.

  • EPSS 0.73%
  • Veröffentlicht 28.10.2022 16:15:15
  • Zuletzt bearbeitet 21.11.2024 07:14:58

Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.