Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.55%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/7/202417/6/2026
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
AnalizadaAlta (7.2)0.76%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/7/202417/6/2026
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
AnalizadaAlta (7.5)58%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read
AnalizadaAlta (8.8)3.2%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/1/202417/6/2026
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.
ModificadaAlta (7.5)0.89%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/10/202317/6/2026
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
AnalizadaAlta (7.5)100%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway10/10/202331/7/2026
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
ModificadaAlta (8)1.3%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Privilege Escalation to root administrator (nsroot)
ModificadaMedia (6.1)2.6%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Reflected Cross-Site Scripting (XSS)
AnalizadaCrítica (9.8)100%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/20235/8/2026
Unauthenticated remote code execution
ModificadaMedia (6.1)81%—Citrix GatewayCitrix Application Delivery Controller10/7/202317/6/2026
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
ModificadaAlta (7.5)1.1%—Citrix Application Delivery ControllerCitrix Gateway10/7/202317/6/2026
Arbitrary file read in Citrix ADC and Citrix Gateway
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaAlta (8.8)0.42%—Edgenexus Application Delivery Controller23/1/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)3.5%—Edgenexus Application Delivery Controller23/1/202317/6/2026
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via…
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activaCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaCrítica (9.8)0.64%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
User login brute force protection functionality bypass
ModificadaCrítica (9.6)0.29%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Remote desktop takeover via phishing
ModificadaCrítica (9.8)1.1%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Unauthorized access to Gateway user capabilities
ModificadaMedia (6.1)0.52%—Citrix GatewayCitrix Application Delivery Controller Firmware28/7/202217/6/2026
Unauthenticated redirection to a malicious website
ModificadaAlta (7.5)0.92%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Sd-wan7/12/202117/6/2026
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
ModificadaAlta (7.5)0.92%—Citrix Application Delivery Controller FirmwareCitrix Gateway7/12/202117/6/2026
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.
ModificadaAlta (8.1)0.84%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway5/8/202117/6/2026
A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.
ModificadaAlta (7.5)0.94%—Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop5/8/202117/6/2026
A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the…