Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.34% | — | Matrix DendriteAI | 17/7/2026 | 17/7/2026 | Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit… | |
| Aplazada | Alta (7.1) | 0.30% | — | Matrix DendriteAI | 17/7/2026 | 17/7/2026 | Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership… | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Citrix Secure Access ClientAI | 14/7/2026 | 15/7/2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI | 14/7/2026 | 15/7/2026 | Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7. | |
| Aplazada | Baja (1.3) | 0.35% | — | Usestrix StrixAI | 13/7/2026 | 13/7/2026 | A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be carried out remotely. The complexity of an… | |
| Aplazada | Crítica (9.4) | 0.17% | — | Citrix XapiAICitrix XenserverAI | 9/7/2026 | 10/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can… | |
| Aplazada | Crítica (9.4) | 0.17% | — | Citrix XenserverAI | 9/7/2026 | 10/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can… | |
| Aplazada | Crítica (9.4) | 0.17% | — | Citrix XenserverAI | 9/7/2026 | 10/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can… | |
| Aplazada | Crítica (9.4) | 0.17% | — | Citrix XenserverAI | 9/7/2026 | 9/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can… | |
| Aplazada | Crítica (9.4) | 0.17% | — | Citrix XenserverAI | 9/7/2026 | 9/7/2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can… | |
| Aplazada | Crítica (9.4) | 0.18% | — | Citrix XapiAI | 9/7/2026 | 29/9/2026 | There are multiple issues. | |
| Analizada | Alta (8.8) | 0.63% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment | |
| Analizada | Alta (8.8) | 1.0% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 27/8/2026 | Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server | |
| Analizada | Alta (8.8) | 0.50% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 1/7/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP | |
| Analizada | Alta (8.7) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Media (6.9) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | |
| Analizada | Alta (7.1) | 0.58% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 30/6/2026 | 2/7/2026 | Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | |
| Aplazada | Alta (7.8) | 0.18% | — | Matrix42 EmpirumAI | 29/6/2026 | 17/7/2026 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of… | |
| Aplazada | Alta (8.5) | 0.17% | — | Matrix42 Remote Control HostAI | 19/6/2026 | 29/9/2026 | Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted… | |
| Analizada | Media (6.1) | 0.15% | — | Dell Powerflex Rack Release Certification Matrix | 17/6/2026 | 6/10/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections. | |
| Pendiente de análisis | Alta (8.8) | 0.38% | — | Citrix CloudAI | 17/6/2026 | 5/10/2026 | In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account. | |
| Pendiente de análisis | Crítica (9.8) | 1.5% | — | 1C BitrixAI | 8/5/2026 | 17/6/2026 | 1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload… | |
| Pendiente de análisis | Media (6.3) | 1.0% | — | Bitrix24AI | 8/5/2026 | 17/6/2026 | Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload… | |
| Analizada | Media (6.5) | 0.39% | — | Jenkins Matrix Authorization Strategy | 29/4/2026 | 17/6/2026 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 23/4/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces… |