Known Vulnerabilities for Nova by OpenStack
Listed below are 10 of the newest known vulnerabilities associated with "Nova" by "OpenStack".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-46448 json | In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placem... | Not Provided | 2026-06-16 | 2026-06-16 |
| CVE-2026-42202 json | nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggl... | Not Provided | 2026-05-08 | 2026-05-11 |
| CVE-2026-29203 json | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbit... | Not Provided | 2026-05-08 | 2026-05-15 |
| CVE-2026-7668 json | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in the l... | Not Provided | 2026-05-02 | 2026-05-20 |
| CVE-2025-31819 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks ... | Not Provided | 2025-04-01 | 2026-04-23 |
| CVE-2025-24612 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ihor Kit Shipping for N... | Not Provided | 2025-01-27 | 2026-04-23 |
| CVE-2025-0419 json | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Informatio... | Not Provided | 2025-09-17 | 2026-06-06 |
| CVE-2024-57977 json | In the Linux kernel, the following vulnerability has been resolved: memcg: fix soft lockup in the OOM process A soft lockup... | Not Provided | 2025-02-27 | 2026-05-12 |
| CVE-2024-6684 json | Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Authent... | Not Provided | 2024-08-12 | 2026-06-03 |
| CVE-2024-4658 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS... | Not Provided | 2024-10-10 | 2026-06-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Nova | 2015.1.4 | |||
| Application | Openstack | Nova | 2015.1.3 | |||
| Application | Openstack | Nova | 2015.1.2 | |||
| Application | Openstack | Nova | 2015.1.1 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2015.1.0 | |||
| Application | Openstack | Nova | 2014.2.4 | |||
| Application | Openstack | Nova | 2014.2.3 | |||
| Application | Openstack | Nova | 2014.2.2 | |||
| Application | Openstack | Nova | 2014.2.1 | |||
| Application | Openstack | Nova | 2014.2.0 | |||
| Application | Openstack | Nova | 2014.2.0 |