Vulnerabilities

Summary — last 7 days

New vulnerabilities2,635▼ 211 vs. last week
Critical / high1,376▲ 147 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedMedium (6.2)0.23%—Kanaka WAC11/8/20246/17/2026
wac commit 385e1 was discovered to contain a heap overflow.
AnalyzedMedium (5.5)0.23%—Kanaka WAC11/8/20246/17/2026
wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.
AnalyzedMedium (6.2)0.23%—Kanaka WAC11/8/20246/17/2026
wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.
AnalyzedMedium (6.2)0.26%—Kanaka WAC11/8/20246/17/2026
wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted wasm file.
ModifiedMedium (4.3)2.2%—Kanaka Novnc4/10/20156/17/2026
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
ModifiedMedium (5.8)0.59%—Novell Kanaka4/7/20136/16/2026
The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, which allows man-in-the-middle attackers to spoof servers via an arbitrary certificate.