Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.34%—Matrix DendriteAI17/7/202617/7/2026
Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit…
AplazadaAlta (7.1)0.30%—Matrix DendriteAI17/7/202617/7/2026
Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership…
Pendiente de análisisMedia (6.8)0.18%—Citrix Secure Access ClientAI14/7/202615/7/2026
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
Pendiente de análisisAlta (8.5)0.17%—Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI14/7/202615/7/2026
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
AplazadaBaja (1.3)0.35%—Usestrix StrixAI13/7/202613/7/2026
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be carried out remotely. The complexity of an…
AplazadaCrítica (9.4)0.17%—Citrix XapiAICitrix XenserverAI9/7/202610/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…
AplazadaCrítica (9.4)0.17%—Citrix XenserverAI9/7/202610/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…
AplazadaCrítica (9.4)0.17%—Citrix XenserverAI9/7/202610/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…
AplazadaCrítica (9.4)0.17%—Citrix XenserverAI9/7/20269/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…
AplazadaCrítica (9.4)0.17%—Citrix XenserverAI9/7/20269/7/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: The pool-admin role is fully privileged. Notably, users with this role can…
AplazadaCrítica (9.4)0.18%—Citrix XapiAI9/7/202629/9/2026
There are multiple issues.
AnalizadaAlta (8.8)0.63%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
AnalizadaAlta (8.8)1.0%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/202627/8/2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AnalizadaAlta (8.8)0.50%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
AnalizadaAlta (8.7)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaMedia (6.9)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaAlta (7.1)0.58%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
AplazadaAlta (7.8)0.18%—Matrix42 EmpirumAI29/6/202617/7/2026
PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of…
AplazadaAlta (8.5)0.17%—Matrix42 Remote Control HostAI19/6/202629/9/2026
Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService and FastViewerRemoteProxy services that allows local users to execute arbitrary code with SYSTEM privileges. Attackers can place a malicious executable in the Program Files directory with a crafted…
AnalizadaMedia (6.1)0.15%—Dell Powerflex Rack Release Certification Matrix17/6/20266/10/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.
Pendiente de análisisAlta (8.8)0.38%—Citrix CloudAI17/6/20265/10/2026
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
Pendiente de análisisCrítica (9.8)1.5%—1C BitrixAI8/5/202617/6/2026
1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload…
Pendiente de análisisMedia (6.3)1.0%—Bitrix24AI8/5/202617/6/2026
Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file. NOTE: this is disputed by the Supplier because this is intended behavior for the high-privileged users who can upload…
AnalizadaMedia (6.5)0.39%—Jenkins Matrix Authorization Strategy29/4/202617/6/2026
Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to…
Pendiente de análisisMedia (5.3)0.36%—Langsmith Python SDKAIMatrix Javascript SDKAI23/4/202617/6/2026
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces…