Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Analizada | Alta (7.5) | 58% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | |
| Analizada | Alta (8.8) | 3.2% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/1/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. | |
| Modificada | Alta (7.5) | 0.89% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/10/2023 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/10/2023 | 31/7/2026 | Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | |
| Modificada | Alta (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modificada | Media (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Modificada | Media (6.1) | 81% | — | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Alta (7.5) | 1.0% | — | Citrix Application Delivery ControllerCitrix Gateway | 26/1/2023 | 17/6/2026 | Unauthenticated denial of service | |
| Modificada | Media (6.5) | 0.99% | — | Citrix GatewayCitrix Application Delivery Controller | 26/1/2023 | 17/6/2026 | Authenticated denial of service | |
| Modificada | Alta (8.8) | 0.42% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 3.5% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via… | |
| Modificada | Media (6.5) | 0.59% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 26/12/2022 | 17/6/2026 | In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update. | |
| Analizada | Crítica (9.8) | 6.7% | ⚠ Explotación activa | Citrix Application Delivery Controller FirmwareCitrix Gateway Firmware | 13/12/2022 | 17/6/2026 | Unauthenticated remote arbitrary code execution | |
| Modificada | Crítica (9.8) | 0.64% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | User login brute force protection functionality bypass | |
| Modificada | Crítica (9.6) | 0.29% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Remote desktop takeover via phishing | |
| Modificada | Crítica (9.8) | 1.1% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Unauthorized access to Gateway user capabilities | |
| Modificada | Media (6.1) | 0.52% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 28/7/2022 | 17/6/2026 | Unauthenticated redirection to a malicious website | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Sd-wan | 7/12/2021 | 17/6/2026 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 7/12/2021 | 17/6/2026 | A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (8.1) | 0.84% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 5/8/2021 | 17/6/2026 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | |
| Modificada | Alta (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… |