Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.22%—Citrix Workspace10/7/202417/6/2026
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
ModificadaMedia (5.3)0.40%—Citrix Workspace10/7/202417/6/2026
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
AnalizadaCrítica (9.4)21%💥 ExploitCitrix Netscaler Console10/7/202417/6/2026
Sensitive information disclosure in NetScaler Console
AnalizadaMedia (5.1)0.55%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/7/202417/6/2026
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
AnalizadaAlta (7.2)0.76%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/7/202417/6/2026
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
AplazadaMedia (4.3)0.50%—Matrix Appservice-ircAI5/7/202417/6/2026
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether…
ModificadaCrítica (9.4)19%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
ModificadaCrítica (9.4)17%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/7/202417/6/2026
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
AnalizadaAlta (8.7)1.5%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+91/7/202417/6/2026
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
ModificadaMedia (6)0.17%—Citrix XenserverCitrix Hypervisor13/6/202417/6/2026
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
AplazadaMedia (5.5)0.19%—Matrix-sdk-cryptoAI14/5/202417/6/2026
The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in…
AplazadaMedia (5.4)0.78%—Basecamp TrixAI7/5/202417/6/2026
Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with markup into the editor. The vulnerability stems from improper sanitization of pasted content, allowing an attacker to embed malicious…
AnalizadaAlta (7.6)4.1%💥 PoCFortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+56/5/202417/6/2026
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that…
AnalizadaMedia (6.5)1.5%—Matrix SynapseFedoraproject Fedora23/4/202417/6/2026
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the…
AplazadaMedia (4.3)0.45%—Matrix Appservice-ircAI12/4/202417/6/2026
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a precondition to the attack, the malicious user…
AnalizadaMedia (5.3)0.37%—Citrix Sd-wan 1000 FirmwareCitrix Sd-wan 110 FirmwareCitrix Sd-wan 1100 FirmwareCitrix Sd-wan 2000 Firmware+812/3/202417/6/2026
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
ModificadaMedia (4.3)0.69%—Jenkins Matrix Project24/1/202417/6/2026
Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers.
ModificadaAlta (7.2)47%—Citrix Virtual Apps AND Desktops18/1/202417/6/2026
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
AnalizadaAlta (7.5)58%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
ModificadaMedia (6.1)75%💥 ExploitCloud Citrix Storefront17/1/202417/6/2026
Cross-site scripting (XSS)
AnalizadaAlta (8.8)3.2%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
ModificadaAlta (7.5)0.73%—MatrixsslRambus TLS Toolkit22/12/202317/6/2026
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded.…
ModificadaAlta (8.8)0.29%—Nkb-bd Preloader Matrix18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1.
ModificadaAlta (8)0.85%—Bitrix241/11/202317/6/2026
Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through…
ModificadaCrítica (9.8)5.0%💥 ExploitBitrix241/11/202317/6/2026
Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator…