Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.44% | — | OSC Open OndemandAI | 14/5/2026 | 17/6/2026 | Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2. | |
| Analizada | Media (6.3) | 0.69% | — | OSC Open Ondemand | 4/3/2026 | 17/6/2026 | Open OnDemand is an open-source high-performance computing portal. The Files application in OnDemand versions prior to 4.0.9 and 4.1.3 is susceptible to malicious input when navigating to a directory. This has been patched in versions 4.0.9 and 4.1.3. Versions below this remain susceptible. | |
| Analizada | Alta (7.6) | 0.20% | — | OSC Open Ondemand | 17/12/2025 | 17/6/2026 | Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to be passed to origin servers. This means malicious users can create an origin server on a compute node that record these headers when unsuspecting users connect to it. Maintainers… | |
| Aplazada | Media (6.9) | 0.29% | — | OSC Open OndemandAI | 20/11/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writable locations in the GEM_PATH. Open OnDemand versions 4.0.8 and 3.1.16 have been patched for this vulnerability. | |
| Aplazada | Media (4.3) | 0.21% | — | OSC Open OndemandAI | 20/11/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to access files outside of the OOD_ALLOWLIST. This vulnerability impacts sites that use the file browser allowlists in all current versions of OOD.… | |
| Aplazada | Media (4.1) | 0.27% | — | TurbovncAINovncAIOSC Open OndemandAI | 9/9/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Prior to versions 3.1.15 and 4.0.7, noVNC interactive applications did not correctly rotate the password when TurboVNC was higher than version 3.1.2. The likelihood of exploitation is low as a user would need to share their link to an active desktop session and the other… | |
| Aplazada | Media (5.4) | 0.31% | — | OSC Open OndemandAI | 11/7/2025 | 17/6/2026 | Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files causing a Denial of Service (DoS) to the ondemand system. This vulnerability is fixed in 3.1.14 and 4.0.6. | |
| Modificada | Media (4.3) | 1.1% | — | OSU Ohio Supercomputer Center Open Ondemand | 26/2/2022 | 17/6/2026 | The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template. | |
| Modificada | Alta (8.8) | 0.45% | — | OSC Open Ondemand | 19/2/2021 | 17/6/2026 | Open OnDemand before 1.5.7 and 1.6.x before 1.6.22 allows CSRF. |