CVE Tools

Opennebula

3 CVEs tracked since 2022. Since Oct 2022, none of them reached CISA KEV.

Opennebula CVEs per month

Oct 2022 to Oct 2022. Point at a month, or focus the strip and use the arrow keys.
Opennebula CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1030

Products

The products that kept showing up in Opennebula's monthly top three, with their CVEs summed over those months.

  1. Opennebula31 month

Latest CVEs

The 8 most recently published vulnerabilities affecting Opennebula.

  1. CVE-2025-56534A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.6.1
  2. CVE-2025-56536A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.6.1
  3. CVE-2025-56535A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.6.1
  4. CVE-2025-56537A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtu...6.1
  5. CVE-2025-54955OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unaut...8.1
  6. CVE-2022-37425The FILES directive inside a VM template allows execution of uploaded files when the template is instantiated, resulting in a Remote Code Execution (RCE) attack.9.9
  7. CVE-2022-37426Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection.4.3
  8. CVE-2022-37424The FILES Directive allows arbitrary files from the frontend system (including sensitive files) to be included when a VM is started from that template, which may result in Information Disclosure.6.5

The record

Peak rank
#186 in Oct 2022
Busiest month shown
Oct 2022, 3 CVEs
Months with a KEV entry
0 since Oct 2022
Monthly snapshots
1 since 2022
Opennebula's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store