Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
433 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.5% | — | Silver-peak Unity Edgeconnect Sd-wan Firmware | 8/9/2019 | 17/6/2026 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to the REST API, such as the rest/json/banners URI. | |
| Modificada | Alta (7.5) | 1.8% | — | Silver-peak Unity Edgeconnect Sd-wan Firmware | 8/9/2019 | 17/6/2026 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a single source. | |
| Modificada | Alta (8.8) | 0.61% | — | Silver-peak Unity Edgeconnect Sd-wan Firmware | 8/9/2019 | 17/6/2026 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. | |
| Modificada | Media (4.6) | 0.84% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+6 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver. | |
| Modificada | Media (5.8) | 1.5% | — | Cisco Sd-wan Firmware | 8/8/2019 | 17/6/2026 | A vulnerability in the packet filtering features of Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious… | |
| Modificada | Crítica (9.8) | 6.3% | — | Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+9 | 19/7/2019 | 17/6/2026 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass… | |
| Modificada | Alta (8.8) | 49% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). | |
| Analizada | Alta (8.8) | 74% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | |
| Modificada | Crítica (9.8) | 39% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | |
| Modificada | Alta (8.8) | 1.9% | — | Cisco Sd-wan Firmware | 20/6/2019 | 17/6/2026 | A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected vManage device. The vulnerability is due to a failure to properly authorize certain user actions in the device configuration. An attacker could… | |
| Modificada | Alta (7.8) | 0.42% | — | Cisco Sd-wan Firmware | 20/6/2019 | 17/6/2026 | A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level privileges to the root user on an affected device. The vulnerability is due to insufficient authorization enforcement. An attacker could exploit this vulnerability by authenticating to the targeted… | |
| Modificada | Alta (8.8) | 4.3% | — | Cisco Sd-wan | 20/6/2019 | 17/6/2026 | A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating… | |
| Modificada | Crítica (9.8) | 65% | — | Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center | 3/6/2019 | 17/6/2026 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | |
| Modificada | Media (5.9) | 0.58% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 8/5/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. | |
| Modificada | Alta (7.7) | 4.3% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+10 | 25/4/2019 | 17/6/2026 | An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net… | |
| Modificada | Alta (8.8) | 3.5% | — | Cisco Vedge 100 FirmwareCisco Vedge 1000 FirmwareCisco Vedge 2000 FirmwareCisco Vedge 5000 Firmware+4 | 24/1/2019 | 17/6/2026 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the save command in the CLI of the affected software. An attacker could exploit this… | |
| Modificada | Alta (7.8) | 0.37% | — | Cisco Vedge 100 FirmwareCisco Vedge 1000 FirmwareCisco Vedge 2000 FirmwareCisco Vedge 5000 Firmware+4 | 24/1/2019 | 17/6/2026 | A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacker to gain elevated privileges on an affected device. The vulnerability is due to a failure to properly validate certain parameters included within the group configuration. An attacker could exploit… | |
| Modificada | Alta (8) | 0.81% | — | Cisco Sd-wanCisco Vsmart Controller | 24/1/2019 | 17/6/2026 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers. The vulnerability is due to an insecure default configuration of the affected system. An attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.8) | 0.45% | — | Cisco Vedge 100 FirmwareCisco Vedge 1000 FirmwareCisco Vedge 2000 FirmwareCisco Vedge 5000 Firmware+4 | 24/1/2019 | 17/6/2026 | A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by… | |
| Modificada | Crítica (9.8) | 2.2% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |