Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)2.7%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request…
ModificadaAlta (7.8)0.36%—Citrix Xenserver23/1/202016/6/2026
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.
ModificadaAlta (7.8)6.9%—Citrix ReceiverCitrix Xenapp Online10/1/202016/6/2026
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.
ModificadaAlta (7.5)3.6%—Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+12/1/202016/6/2026
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
ModificadaAlta (8.1)9.7%—Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+12/1/202016/6/2026
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware27/12/201912/8/2026
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
ModificadaCrítica (9.1)3.4%—Squiz Matrix11/12/201917/6/2026
An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_upload.inc in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can delete arbitrary files from the server during…
ModificadaAlta (7.5)4.8%—Squiz Matrix11/12/201917/6/2026
An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and 5.5.3 prior to 5.5.3.3 where a user can trigger arbitrary unserialization of a PHP object from a packages/cms/page_templates/page_remote_content/page_remote_content.inc POST parameter during…
ModificadaAlta (7.8)0.57%—Aviatrix VPN Client5/12/201917/6/2026
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
ModificadaAlta (7.8)0.72%—Aviatrix VPN Client5/12/201917/6/2026
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
ModificadaCrítica (9.8)0.86%—Matrix Synapse8/11/201917/6/2026
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
ModificadaCrítica (9.8)1.5%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware21/10/201917/6/2026
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance…
ModificadaAlta (8.8)1.3%—Citrix Application Delivery Management9/10/201917/6/2026
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
ModificadaMedia (5.9)1.2%—Matrixssl3/10/201917/6/2026
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because crypto/pubkey/ecc_math.c scalar multiplication leaks…
ModificadaAlta (7.5)1.1%—Humanica Humatrix10/9/201917/6/2026
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
AnalizadaAlta (7.5)30%⚠ Explotación activa💥 ExploitCitrix Storefront Server29/8/201917/6/2026
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ModificadaCrítica (9.8)2.4%—Humanica Humatrix 718/8/201917/6/2026
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the…
ModificadaMedia (5.3)1.3%—Humanica Humatrix 718/8/201917/6/2026
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.
ModificadaAlta (7.5)2.1%—Humanica Humatrix 712/8/201917/6/2026
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' information on the website via a modified selApp variable to personalData/resumeDetail.cfm. This includes personal information and other sensitive data.
ModificadaCrítica (9.8)3.6%—Matrixssl29/7/201917/6/2026
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value…
ModificadaAlta (8.8)49%—Citrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
AnalizadaAlta (8.8)74%⚠ Explotación activa💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
ModificadaCrítica (9.8)39%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
ModificadaCrítica (9.8)43%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).