Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.9%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware10/7/202017/6/2026
Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.
ModificadaCrítica (9.8)2.0%—Bitrix2424/6/202017/6/2026
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta name="og:image" content="' followed by an intranet URL.
ModificadaMedia (6.1)4.5%💥 ExploitBitrix2424/6/202017/6/2026
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
ModificadaMedia (5.3)1.4%—Citrix Xenapp11/6/202017/6/2026
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.8)0.58%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
ModificadaAlta (7.8)0.57%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
ModificadaMedia (6.1)0.86%—Bitrix241/6/202017/6/2026
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
ModificadaCrítica (9.8)2.3%—Aviatrix ControllerAviatrix GatewayAviatrix VPN Client22/5/202017/6/2026
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
ModificadaMedia (6.5)0.51%—Aviatrix Controller22/5/202017/6/2026
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
ModificadaAlta (7.5)0.75%—Aviatrix Controller22/5/202017/6/2026
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
ModificadaAlta (7.5)1.5%—Aviatrix ControllerAviatrix Gateway22/5/202017/6/2026
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
ModificadaMedia (5.3)1.4%—Aviatrix ControllerAviatrix VPN Client22/5/202017/6/2026
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
ModificadaAlta (8.8)0.58%—Aviatrix Controller22/5/202017/6/2026
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.
ModificadaAlta (7.5)4.6%—Citrix Sharefile Storagezones Controller7/5/202017/6/2026
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud…
ModificadaAlta (7.5)27%💥 ExploitCitrix Sharefile Storagezones Controller7/5/202017/6/2026
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are…
ModificadaAlta (7.5)14%💥 PoCCitrix Sharefile Storagezones Controller7/5/202017/6/2026
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version…
ModificadaAlta (8.8)65%💥 ExploitNetfortris Trixbox1/5/202017/6/2026
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects:…
ModificadaCrítica (9.8)2.3%—Aviatrix Openvpn16/4/202017/6/2026
The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.
ModificadaMedia (5.4)0.55%—Matrix42 Workspace Management15/4/202017/6/2026
The Search parameter of the Software Catalogue section of Matrix42 Workspace Management 9.1.2.2765 and below accepts unfiltered parameters that lead to multiple reflected XSS issues.
ModificadaMedia (5.4)0.77%—Matrix42 Workspace Management15/4/202017/6/2026
Matrix42 Workspace Management 9.1.2.2765 and below allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software.
ModificadaAlta (7.5)0.43%—Inextrix Astpp20/3/202017/6/2026
An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have strong random keys, as demonstrated by use of the 8YSDaBtDHAB3EQkxPAyTz2I5DttzA9uR private key and the r)fddEw232f encryption key.
ModificadaMedia (5.9)0.59%—Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center16/3/202017/6/2026
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
ModificadaMedia (6.1)0.78%—Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center10/3/202017/6/2026
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
ModificadaMedia (5.4)1.5%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not…
ModificadaAlta (7.5)2.0%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization
Orbitaley — Vulnerabilidades