Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.36% | — | Intel Matrix Storage Manager | 14/3/2019 | 17/6/2026 | Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.9) | 3.5% | — | Jenkins Matrix ProjectRedhat Openshift Container Platform | 8/3/2019 | 17/6/2026 | A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM. | |
| Modificada | Media (5.9) | 2.3% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 22/2/2019 | 17/6/2026 | Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5… | |
| Modificada | Media (5.6) | 0.43% | — | XENCitrix XenserverDebian Linux | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation. | |
| Modificada | Alta (7.8) | 0.41% | — | XENDebian LinuxCitrix Xenserver | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | |
| Modificada | Alta (7.8) | 0.41% | — | XENDebian LinuxCitrix Xenserver | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | |
| Modificada | Media (4.8) | 0.83% | — | Citrix Netscaler Gateway Firmware | 24/10/2018 | 17/6/2026 | Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Citrix Xenmobile Server | 24/10/2018 | 17/6/2026 | * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal… | |
| Modificada | Alta (7.8) | 2.9% | — | Citrix Xenmobile Server | 24/10/2018 | 17/6/2026 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor… | |
| Modificada | Crítica (9.8) | 2.2% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 1.9% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 2.0% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 11% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 3.6% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Media (4.3) | 1.1% | — | Citrix Sharefile Storagezones Controller | 26/9/2018 | 17/6/2026 | Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. | |
| Modificada | Baja (3.1) | 1.1% | — | Citrix Sharefile Storagezones Controller | 26/9/2018 | 17/6/2026 | Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | |
| Modificada | Alta (8.8) | 1.5% | — | Matrix SynapseDebian Linux | 18/9/2018 | 17/6/2026 | Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation. | |
| Modificada | Crítica (9.8) | 56% | — | Citrix Xenserver | 15/8/2018 | 17/6/2026 | Citrix XenServer 7.1 and newer allows Directory Traversal. | |
| Modificada | Alta (7.5) | 2.4% | — | Tibco Activematrix BusinessworksActivematrix Businessworks Distribution FOR Tibco Silver Fabric | 8/8/2018 | 17/6/2026 | The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages,… | |
| Modificada | Crítica (9.9) | 4.4% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+5 | 27/7/2018 | 17/6/2026 | A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU… | |
| Modificada | Crítica (9.9) | 3.6% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+6 | 27/7/2018 | 17/6/2026 | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary… | |
| Modificada | Media (6.8) | 0.35% | — | Threatmetrix SDK | 24/7/2018 | 17/6/2026 | On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS connections, which may allow an attacker to perform a man-in-the-middle (MITM) attack. ThreatMetrix is a security library for mobile applications, which aims to provide fraud prevention and device… | |
| Modificada | Crítica (9.1) | 3.6% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+6 | 3/7/2018 | 17/6/2026 | Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute… | |
| Modificada | Media (5.6) | 0.63% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core M+10 | 21/6/2018 | 17/6/2026 | System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. | |
| Modificada | Media (4.7) | 0.27% | — | Matrixssl | 15/6/2018 | 17/6/2026 | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. |