Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)43%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
ModificadaCrítica (9.8)40%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).
ModificadaCrítica (9.8)40%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
ModificadaMedia (6.5)1.9%—Citrix Xenserver11/7/201917/6/2026
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
ModificadaCrítica (9.8)1.6%—Matrixssl9/7/201917/6/2026
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
ModificadaCrítica (9.8)1.5%—Citrix Appdna24/6/201917/6/2026
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
ModificadaCrítica (10)1.5%—Citrix Application Delivery Management5/6/201917/6/2026
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
ModificadaCrítica (9.1)2.6%—Citrix Xenmobile Server5/6/201917/6/2026
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.
ModificadaCrítica (9.8)65%—Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center3/6/201917/6/2026
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
AnalizadaCrítica (9.8)8.1%⚠ Explotación activaCitrix ReceiverCitrix Workspace22/5/201912/8/2026
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
ModificadaAlta (7.5)1.5%—Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware22/5/201917/6/2026
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
ModificadaMedia (5.9)1.2%—Citrix Sharefile13/5/201917/6/2026
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using…
ModificadaAlta (7.5)2.0%—Citrix Sharefile13/5/201917/6/2026
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
ModificadaAlta (7.5)1.8%—Matrix SydentMatrix Synapse9/5/201917/6/2026
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
ModificadaMedia (5.9)0.58%—Citrix Netscaler Sd-wanCitrix Sd-wan8/5/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
ModificadaMedia (6.1)1.1%—Tibco Activematrix BPMTibco Silver Fabric Enabler24/4/201917/6/2026
The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL could trick a user into visiting a…
ModificadaMedia (4.6)0.78%—Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler24/4/201917/6/2026
The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contains vulnerabilities where an authenticated user can change settings that can theoretically adversely impact other users. Affected…
ModificadaCrítica (9.8)2.5%—Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+124/4/201917/6/2026
The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver…
ModificadaAlta (8.8)2.1%—Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+124/4/201917/6/2026
The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric,…
ModificadaAlta (8.8)0.95%—Tibco Activematrix BPMTibco Activematrix Policy DirectorTibco Activematrix Service BUSTibco Activematrix Service Grid+124/4/201917/6/2026
The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric…
ModificadaMedia (6.1)0.69%—Tibco Activematrix Business Process ManagementTibco Silver Fabric Enabler24/4/201917/6/2026
The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain cross site scripting (XSS) and cross-site request forgery…
ModificadaMedia (5.9)1.9%—Matrix Sydent19/4/201917/6/2026
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns…
ModificadaAlta (8.1)2.9%—Tibco Activematrix Businessworks9/4/201917/6/2026
The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that theoretically allows unauthenticated HTTP requests to be processed by the BusinessWorks engine even when authentication is required. This possibility is restricted to circumstances where HTTP "Basic…
ModificadaCrítica (9.8)1.4%—Matrixssl8/4/201917/6/2026
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_pub.c.
ModificadaAlta (7.5)2.4%—Matrix SynapseFedoraproject Fedora21/3/201917/6/2026
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Orbitaley — Vulnerabilidades