Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 295 respecto a la semana anterior
Críticas / altas1347▲ 81 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

3 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.1)0.27%—TurbovncAINovncAIOSC Open OndemandAI9/9/202517/6/2026
Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other…
ModificadaMedia (6.1)4.8%—NovncDebian LinuxCanonical Ubuntu LinuxRedhat Openstack25/9/201917/6/2026
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
ModificadaMedia (4.3)2.2%—Kanaka Novnc10/4/201517/6/2026
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.