Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
433 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 2.0% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 11% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 3.6% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 1.1% | — | Cisco Sd-wan | 5/10/2018 | 17/6/2026 | A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by supplying a system image signed with a crafted certificate to… | |
| Analizada | Alta (8.1) | 86% | ⚠ Explotación activa💥 Exploit | Vmware NSX Sd-wan BY Velocloud | 11/6/2018 | 17/6/2026 | VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful… | |
| Modificada | Alta (7.5) | 2.8% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler GatewayCitrix Netscaler Sd-wan | 1/3/2018 | 17/6/2026 | Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote… | |
| Analizada | Crítica (9.8) | 73% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Sd-wan | 20/7/2017 | 17/6/2026 | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID. |