Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

354 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.0%—Citrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware17/11/201517/6/2026
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified…
ModificadaMedia (4.3)1.00%—Citrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/11/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote…
ModificadaMedia (5)1.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Gateway Firmware17/11/201517/6/2026
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.
ModificadaMedia (6.8)2.4%—Openstack Image Registry AND Delivery Service (glance)26/10/201517/6/2026
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability…
ModificadaMedia (5.5)2.1%—Openstack Image Registry AND Delivery Service (glance)26/10/201517/6/2026
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
ModificadaMedia (4.3)1.4%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified…
ModificadaAlta (10)3.2%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/9/201517/6/2026
Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the…
ModificadaAlta (9)4.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware16/7/201517/6/2026
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to…
ModificadaMedia (6.8)0.90%—Cisco Headend Digital Broadband Delivery System2/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Cisco Headend Digital Broadband Delivery System allows remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (4.3)1.8%—Cisco Videoscape ConductorCisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.
ModificadaMedia (5)1.9%—Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Headend System Release allows remote attackers to read temporary script files or archive files, and consequently obtain sensitive information, via a crafted header in an HTTP request, aka Bug ID CSCus44909.
ModificadaAlta (7.8)3.4%—Cisco DTA Control SystemCisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco DTA Control System (DTACS) 4.0.0.9 and Cisco Headend System Release allow remote attackers to cause a denial of service (CPU and memory consumption, and TCP service outage) via (1) a SYN flood or (2) another type of TCP traffic flood, aka Bug IDs CSCus50642, CSCus50662, CSCus50625, CSCus50657, and CSCus68315.
ModificadaMedia (5)2.0%—Cisco Headend Digital Broadband Delivery SystemCisco Headend System Release30/5/201517/6/2026
Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097.
ModificadaMedia (4.3)1.5%—Cisco Headend Digital Broadband Delivery System30/5/201517/6/2026
CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks, via a crafted request, aka Bug ID CSCur25580.
ModificadaMedia (4.3)1.5%—Cisco Headend Digital Broadband Delivery System15/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in dncs 7.0.0.12 in Cisco Headend Digital Broadband Delivery System allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in a (1) GET or (2) POST request, aka Bug ID CSCur25604.
ModificadaAlta (7.8)2.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware12/5/201517/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.
ModificadaMedia (5.8)1.2%—Ericsson Drutt Mobile Service Delivery Platform6/4/201517/6/2026
Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to jsp/start-3pi-manager.jsp.
ModificadaMedia (5)27%💥 ExploitEricsson Drutt Mobile Service Delivery Platform6/4/201517/6/2026
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.
ModificadaMedia (4.3)1.7%—Ericsson Drutt Mobile Service Delivery Platform6/4/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Report Viewer in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4.x, 5.x, and 6.x allow remote attackers to inject arbitrary web script or HTML via the (1) portal, (2) fromDate, (3) toDate, (4) fromTime, (5) toTime, (6) kword, (7) uname, (8) pname, (9)…
ModificadaMedia (5)1.5%—Cisco Videoscape Delivery System FOR Internet Streamer20/3/201517/6/2026
The DNS implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.2(1) allows remote attackers to cause a denial of service (CPU consumption and network-resource consumption) via crafted packets, aka Bug ID CSCun15911.
ModificadaMedia (4)2.1%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than…
ModificadaMedia (4)2.0%—Openstack Image Registry AND Delivery Service (glance)24/2/201517/6/2026
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a…
ModificadaMedia (4)2.9%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)23/1/201517/6/2026
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
ModificadaMedia (6.5)2.8%—Openstack Image Registry AND Delivery Service (glance)21/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaMedia (5.5)2.8%—Redhat OpenstackOpenstack Image Registry AND Delivery Service (glance)7/1/201517/6/2026
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.