Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 7.3% | — | Citrix Xenmobile Server | 13/4/2022 | 17/6/2026 | Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. | |
| Modificada | Alta (8.8) | 5.7% | — | Citrix Xenmobile Server | 13/4/2022 | 17/6/2026 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges. | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Bitrix24 | 22/3/2022 | 17/6/2026 | In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote unauthenticated attacker can execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.25% | — | Mirametrix Glance | 13/3/2022 | 17/6/2026 | Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this is unrelated to products from the glance.com and glance.net websites. | |
| Modificada | Media (4.4) | 0.17% | — | Citrix Federated Authentication Service | 10/3/2022 | 17/6/2026 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if… | |
| Modificada | Alta (7.8) | 0.22% | — | Citrix Workspace | 9/2/2022 | 17/6/2026 | An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. | |
| Modificada | Media (6.5) | 1.1% | — | Twistedmatrix TreqDebian Linux | 1/2/2022 | 17/6/2026 | treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies").… | |
| Modificada | Media (5.4) | 82% | — | Jenkins Matrix ProjectOracle Communications Cloud Native Core Automated Test Suite | 12/1/2022 | 17/6/2026 | Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission. | |
| Modificada | Crítica (9.8) | 2.0% | — | Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+2 | 14/12/2021 | 17/6/2026 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to… | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Sd-wan | 7/12/2021 | 17/6/2026 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 7/12/2021 | 17/6/2026 | A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (7.5) | 1.7% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+21 | 24/11/2021 | 17/6/2026 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings… | |
| Modificada | Crítica (9.8) | 3.3% | — | Zoom MeetingsZoom Meetings FOR BlackberryZoom Meetings FOR IntuneZoom Meetings FOR Chrome OS+22 | 24/11/2021 | 17/6/2026 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client… | |
| Modificada | Alta (7.5) | 1.6% | — | Matrix SynapseFedoraproject Fedora | 23/11/2021 | 17/6/2026 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories… | |
| Analizada | Crítica (9.8) | 54% | ⚠ Explotación activa💥 PoC | Citrix Sharefile Storagezones Controller | 23/9/2021 | 17/6/2026 | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller. | |
| Modificada | Media (5.9) | 0.66% | — | Matrix ElementMatrix-android-sdk2 | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by… | |
| Modificada | Media (5.9) | 0.66% | — | Matrix Javascript SDK | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in… | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Aviatrix Controller | 13/9/2021 | 17/6/2026 | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal. | |
| Modificada | Baja (3.1) | 1.5% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility.… | |
| Modificada | Baja (3.1) | 0.90% | — | Matrix SynapseFedoraproject Fedora | 31/8/2021 | 17/6/2026 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room… | |
| Modificada | Alta (7.5) | 0.41% | — | Citrix Sharefile Storagezones Controller | 16/8/2021 | 17/6/2026 | An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously selected “Enable Encryption” in the ShareFile… | |
| Modificada | Alta (7.8) | 0.25% | — | Citrix Virtual Apps AND DesktopsCitrix XenappCitrix Xendesktop | 5/8/2021 | 17/6/2026 | A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM. | |
| Modificada | Alta (8.1) | 0.84% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 5/8/2021 | 17/6/2026 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | |
| Modificada | Media (6.5) | 0.92% | — | Citrix Application Delivery ManagementCitrix Gateway | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication… | |
| Modificada | Alta (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… |