Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.7% | — | Citrix Gateway Firmware | 6/3/2020 | 17/6/2026 | Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request… | |
| Modificada | Alta (7.8) | 0.36% | — | Citrix Xenserver | 23/1/2020 | 16/6/2026 | Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges. | |
| Modificada | Alta (7.8) | 6.9% | — | Citrix ReceiverCitrix Xenapp Online | 10/1/2020 | 16/6/2026 | Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver. | |
| Modificada | Alta (7.5) | 3.6% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312. | |
| Modificada | Alta (8.1) | 9.7% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 27/12/2019 | 12/8/2026 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | |
| Modificada | Crítica (9.1) | 3.4% | — | Squiz Matrix | 11/12/2019 | 17/6/2026 | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during… | |
| Modificada | Alta (7.5) | 4.8% | — | Squiz Matrix | 11/12/2019 | 17/6/2026 | An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during… | |
| Modificada | Alta (7.8) | 0.57% | — | Aviatrix VPN Client | 5/12/2019 | 17/6/2026 | Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. | |
| Modificada | Alta (7.8) | 0.72% | — | Aviatrix VPN Client | 5/12/2019 | 17/6/2026 | An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS. | |
| Modificada | Crítica (9.8) | 0.86% | — | Matrix Synapse | 8/11/2019 | 17/6/2026 | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers. | |
| Modificada | Crítica (9.8) | 1.5% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 21/10/2019 | 17/6/2026 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance… | |
| Modificada | Alta (8.8) | 1.3% | — | Citrix Application Delivery Management | 9/10/2019 | 17/6/2026 | Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control. | |
| Modificada | Media (5.9) | 1.2% | — | Matrixssl | 3/10/2019 | 17/6/2026 | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because crypto/pubkey/ecc_math.c scalar multiplication leaks… | |
| Modificada | Alta (7.5) | 1.1% | — | Humanica Humatrix | 10/9/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | |
| Analizada | Alta (7.5) | 30% | ⚠ Explotación activa💥 Exploit | Citrix Storefront Server | 29/8/2019 | 17/6/2026 | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. | |
| Modificada | Crítica (9.8) | 2.4% | — | Humanica Humatrix 7 | 18/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the… | |
| Modificada | Media (5.3) | 1.3% | — | Humanica Humatrix 7 | 18/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI. | |
| Modificada | Alta (7.5) | 2.1% | — | Humanica Humatrix 7 | 12/8/2019 | 17/6/2026 | The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resumeDetail.cfm. This includes personal information and other sensitive data. | |
| Modificada | Crítica (9.8) | 3.6% | — | Matrixssl | 29/7/2019 | 17/6/2026 | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value… | |
| Modificada | Alta (8.8) | 49% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). | |
| Analizada | Alta (8.8) | 74% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | |
| Modificada | Crítica (9.8) | 39% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). |