Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.1%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.…
AnalizadaAlta (7.5)0.29%—Omnissa Unified Access Gateway17/4/202517/6/2026
Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway3/4/20254/8/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
ModificadaAlta (8.3)95%💥 ExploitIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway13/2/202417/6/2026
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.
ModificadaMedia (6.7)22%—Okta Access Gateway2/4/202117/6/2026
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
ModificadaCrítica (9.8)30%—Microsoft Forefront Unified Access Gateway5/7/201817/6/2026
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.
ModificadaCrítica (9.8)3.8%—Vmware Horizon ViewVmware Unified Access Gateway8/6/201717/6/2026
VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
ModificadaMedia (6.8)4.0%—Citrix Access Gateway Plug-in12/8/201416/6/2026
Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based…
ModificadaMedia (5)1.7%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery Controller16/7/201417/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.
ModificadaMedia (4.3)1.7%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway16/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)15%—Citrix Access Gateway Plug-in18/6/201416/6/2026
Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.
ModificadaMedia (4.3)1.2%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway2/5/201417/6/2026
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)1.1%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller1/5/201417/6/2026
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.
ModificadaAlta (10)1.9%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway1/5/201417/6/2026
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.
ModificadaMedia (5.4)1.5%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway25/4/201316/6/2026
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.
ModificadaMedia (5)1.4%—Citrix Access Gateway19/3/201316/6/2026
Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors.
ModificadaMedia (5)36%—Microsoft Forefront Unified Access Gateway10/4/201216/6/2026
Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
ModificadaMedia (5.8)11%—Microsoft Forefront Unified Access Gateway10/4/201216/6/2026
Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."
ModificadaMedia (5)17%—Microsoft Forefront Unified Access Gateway12/10/201116/6/2026
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."
ModificadaAlta (9.3)17%—Microsoft Forefront Unified Access Gateway12/10/201116/6/2026
Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability."
ModificadaMedia (4.3)8.4%—Microsoft Forefront Unified Access Gateway12/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability."
ModificadaMedia (4.3)8.3%—Microsoft Forefront Unified Access Gateway12/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability."
ModificadaMedia (4.3)11%—Microsoft Forefront Unified Access Gateway12/10/201116/6/2026
CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response…
ModificadaAlta (9.3)1.5%—Citrix Access Gateway21/7/201116/6/2026
The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code…
ModificadaAlta (9.3)56%💥 ExploitCitrix Access Gateway21/7/201116/6/2026
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data.
Orbitaley — Vulnerabilidades