Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.22% | — | Citrix Workspace | 10/7/2024 | 17/6/2026 | Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 | |
| Modificada | Media (5.3) | 0.40% | — | Citrix Workspace | 10/7/2024 | 17/6/2026 | Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5 | |
| Analizada | Crítica (9.4) | 21% | 💥 Exploit | Citrix Netscaler Console | 10/7/2024 | 17/6/2026 | Sensitive information disclosure in NetScaler Console | |
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Aplazada | Media (4.3) | 0.50% | — | Matrix Appservice-ircAI | 5/7/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether… | |
| Modificada | Crítica (9.4) | 19% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely | |
| Modificada | Crítica (9.4) | 17% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/7/2024 | 17/6/2026 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized | |
| Analizada | Alta (8.7) | 1.5% | 💥 Exploit | ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+9 | 1/7/2024 | 17/6/2026 | Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | |
| Modificada | Media (6) | 0.17% | — | Citrix XenserverCitrix Hypervisor | 13/6/2024 | 17/6/2026 | An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive. | |
| Aplazada | Media (5.5) | 0.19% | — | Matrix-sdk-cryptoAI | 14/5/2024 | 17/6/2026 | The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in… | |
| Aplazada | Media (5.4) | 0.78% | — | Basecamp TrixAI | 7/5/2024 | 17/6/2026 | Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from the web or other documents with markup into the editor. The vulnerability stems from improper sanitization of pasted content, allowing an attacker to embed malicious… | |
| Analizada | Alta (7.6) | 4.1% | 💥 PoC | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Analizada | Media (6.5) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 23/4/2024 | 17/6/2026 | Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the… | |
| Aplazada | Media (4.3) | 0.45% | — | Matrix Appservice-ircAI | 12/4/2024 | 17/6/2026 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a message if a malicious user sends a Matrix reply to an event ID they don't have access to. As a precondition to the attack, the malicious user… | |
| Analizada | Media (5.3) | 0.37% | — | Citrix Sd-wan 1000 FirmwareCitrix Sd-wan 110 FirmwareCitrix Sd-wan 1100 FirmwareCitrix Sd-wan 2000 Firmware+8 | 12/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP. | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Matrix Project | 24/1/2024 | 17/6/2026 | Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace any config.xml files on the Jenkins controller file system with content not controllable by the attackers. | |
| Modificada | Alta (7.2) | 47% | — | Citrix Virtual Apps AND Desktops | 18/1/2024 | 17/6/2026 | Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | |
| Analizada | Alta (7.5) | 58% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | |
| Modificada | Media (6.1) | 75% | 💥 Exploit | Cloud Citrix Storefront | 17/1/2024 | 17/6/2026 | Cross-site scripting (XSS) | |
| Analizada | Alta (8.8) | 3.2% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. | |
| Modificada | Alta (7.5) | 0.73% | — | MatrixsslRambus TLS Toolkit | 22/12/2023 | 17/6/2026 | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in the TLS 1.3 server. An attacked device calculates an SHA-2 hash over at least 65 KB (in RAM). With a large number of crafted TLS messages, the CPU becomes heavily loaded.… | |
| Modificada | Alta (8.8) | 0.29% | — | Nkb-bd Preloader Matrix | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lukman Nakib Preloader Matrix.This issue affects Preloader Matrix: from n/a through 2.0.1. | |
| Modificada | Alta (8) | 0.85% | — | Bitrix24 | 1/11/2023 | 17/6/2026 | Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted HTML file through… | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Bitrix24 | 1/11/2023 | 17/6/2026 | Global variable extraction in bitrix/modules/main/tools.php in Bitrix24 22.0.300 allows unauthenticated remote attackers to (1) enumerate attachments on the server and (2) execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator… |