Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 295 respecto a la semana anterior
Críticas / altas1347▲ 81 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.1) | 0.27% | — | TurbovncAINovncAIOSC Open OndemandAI | 9/9/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other… | |
| Modificada | Media (6.1) | 4.8% | — | NovncDebian LinuxCanonical Ubuntu LinuxRedhat Openstack | 25/9/2019 | 17/6/2026 | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name. | |
| Modificada | Media (4.3) | 2.2% | — | Kanaka Novnc | 10/4/2015 | 17/6/2026 | noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. |