<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:35:51.618617+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-34721</id>
    <title>cnvd-2019-34721</title>
    <updated>2026-10-05T15:35:51.640358+00:00</updated>
    <content>cnvd-2019-34721</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-34721"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-80357</id>
    <title>EUVD-2026-80357</title>
    <updated>2026-10-05T15:35:51.640396+00:00</updated>
    <content>EUVD-2026-80357</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-80357"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-18635</id>
    <title>fkie_cve-2017-18635</title>
    <updated>2026-10-05T15:35:51.640409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-18635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-49rv-g7w5-m8xx</id>
    <title>GHSA-49rv-g7w5-m8xx — Cross-Site Scripting in @novnc/novnc</title>
    <updated>2026-10-05T15:35:51.640439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @novnc/novnc</p>
<p>Versions of `@novnc/novnc` prior to 0.6.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to validate input from the remote VNC server such as the VNC server name. This allows an attacker in control of the remote server to execute arbitrary JavaScript in the noVNC web page. It affects any users of `include/ui.js` and users of `vnc_auto.html` and `vnc.html`.</p>
<p>## Recommendation</p>
<p>Upgrade to version 0.6.2 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-49rv-g7w5-m8xx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-18635</id>
    <title>gsd-2017-18635</title>
    <updated>2026-10-05T15:35:51.640465+00:00</updated>
    <content>gsd-2017-18635</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-18635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0754</id>
    <title>RHSA-2020:0754 — Red Hat Security Advisory: novnc security update</title>
    <updated>2026-10-05T15:35:51.640476+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>novnc: XSS vulnerability via the messages propagated to the status field</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18635</id>
    <title>UBUNTU-CVE-2017-18635</title>
    <updated>2026-10-05T15:35:51.640493+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: novnc, Ubuntu:18.04:LTS: novnc</p>
<p>An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-18635"/>
  </entry>
</feed>
