Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.… | |
| Analizada | Alta (7.5) | 0.29% | — | Omnissa Unified Access Gateway | 17/4/2025 | 17/6/2026 | Omnissa UAG contains a Cross-Origin Resource Sharing (CORS) bypass vulnerability. A malicious actor with network access to UAG may be able to bypass administrator-configured CORS restrictions to gain access to sensitive networks. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 3/4/2025 | 4/8/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Modificada | Alta (8.3) | 95% | 💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 13/2/2024 | 17/6/2026 | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication. | |
| Modificada | Media (6.7) | 22% | — | Okta Access Gateway | 2/4/2021 | 17/6/2026 | A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account. | |
| Modificada | Crítica (9.8) | 30% | — | Microsoft Forefront Unified Access Gateway | 5/7/2018 | 17/6/2026 | uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome. | |
| Modificada | Crítica (9.8) | 3.8% | — | Vmware Horizon ViewVmware Unified Access Gateway | 8/6/2017 | 17/6/2026 | VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway. | |
| Modificada | Media (6.8) | 4.0% | — | Citrix Access Gateway Plug-in | 12/8/2014 | 16/6/2026 | Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based… | |
| Modificada | Media (5) | 1.7% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery Controller | 16/7/2014 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie. | |
| Modificada | Media (4.3) | 1.7% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 16/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 15% | — | Citrix Access Gateway Plug-in | 18/6/2014 | 16/6/2026 | Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header. | |
| Modificada | Media (4.3) | 1.2% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 2/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 1.1% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller | 1/5/2014 | 17/6/2026 | Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation. | |
| Modificada | Alta (10) | 1.9% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway | 1/5/2014 | 17/6/2026 | Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors. | |
| Modificada | Media (5.4) | 1.5% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/4/2013 | 16/6/2026 | Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors. | |
| Modificada | Media (5) | 1.4% | — | Citrix Access Gateway | 19/3/2013 | 16/6/2026 | Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors. | |
| Modificada | Media (5) | 36% | — | Microsoft Forefront Unified Access Gateway | 10/4/2012 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability." | |
| Modificada | Media (5.8) | 11% | — | Microsoft Forefront Unified Access Gateway | 10/4/2012 | 16/6/2026 | Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability." | |
| Modificada | Media (5) | 17% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash." | |
| Modificada | Alta (9.3) | 17% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 provides the MicrosoftClient.jar file containing a signed Java applet, which allows remote attackers to execute arbitrary code on client machines via unspecified vectors, aka "Poisoned Cup of Code Execution Vulnerability." | |
| Modificada | Media (4.3) | 8.4% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Default Reflected XSS Vulnerability." | |
| Modificada | Media (4.3) | 8.3% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "ExcelTable Reflected XSS Vulnerability." | |
| Modificada | Media (4.3) | 11% | — | Microsoft Forefront Unified Access Gateway | 12/10/2011 | 16/6/2026 | CRLF injection vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via unspecified vectors, aka "ExcelTable Response… | |
| Modificada | Alta (9.3) | 1.5% | — | Citrix Access Gateway | 21/7/2011 | 16/6/2026 | The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which allows man-in-the-middle attackers to execute arbitrary code… | |
| Modificada | Alta (9.3) | 56% | 💥 Exploit | Citrix Access Gateway | 21/7/2011 | 16/6/2026 | Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP header data. |