Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Matrix Synapse | 14/6/2018 | 17/6/2026 | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force. | |
| Modificada | Alta (7.5) | 1.8% | — | Matrix Synapse | 13/6/2018 | 17/6/2026 | The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly. | |
| Modificada | Alta (8.1) | 1.2% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | |
| Modificada | Crítica (9.8) | 6.8% | 💥 Exploit | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | |
| Modificada | Alta (7.5) | 1.2% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3. | |
| Modificada | Media (6.1) | 0.73% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | |
| Modificada | Alta (7.8) | 0.82% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | |
| Modificada | Media (6.1) | 0.67% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3. | |
| Modificada | Crítica (9.8) | 1.2% | — | Citrix Xenmobile Server | 23/5/2018 | 17/6/2026 | There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | |
| Modificada | Crítica (9.8) | 6.2% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 17/5/2018 | 17/6/2026 | The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.8) | 18% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 8/5/2018 | 17/6/2026 | A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)… | |
| Modificada | Alta (7.5) | 1.5% | — | Matrix Synapse | 2/5/2018 | 17/6/2026 | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018. | |
| Modificada | Media (6.1) | 1.2% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface. | |
| Modificada | Alta (7.5) | 4.4% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 6/3/2018 | 17/6/2026 | Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request. | |
| Modificada | Crítica (9.8) | 4.1% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system. | |
| Modificada | Alta (7.5) | 2.3% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system. | |
| Modificada | Alta (7.8) | 0.39% | — | Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Alta (7.5) | 2.8% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler GatewayCitrix Netscaler Sd-wan | 1/3/2018 | 17/6/2026 | Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote… | |
| Modificada | Media (6.5) | 39% | 💥 Exploit | Netfortris Trixbox | 16/2/2018 | 17/6/2026 | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php. | |
| Modificada | Media (5.4) | 0.60% | — | Netfortris Trixbox | 16/2/2018 | 17/6/2026 | trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php. | |
| Modificada | Alta (8.8) | 50% | 💥 Exploit | Netfortris Trixbox | 16/2/2018 | 17/6/2026 | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php. | |
| Modificada | Media (4.3) | 0.73% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | |
| Modificada | Media (4.3) | 0.73% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | |
| Modificada | Media (4.3) | 0.73% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. | |
| Modificada | Media (5.3) | 3.2% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found. |