Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
923 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote information disclosure vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Media (6.5) | 0.98% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Media (5.3) | 1.5% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Media (5.4) | 0.95% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Alta (8.8) | 0.73% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A CSRF vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Media (6.5) | 1.6% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found. | |
| Modificada | Baja (3.5) | 0.60% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote HTTP parameter Pollution vulnerability in HPE Matrix Operating Environment version 7.6 was found. | |
| Modificada | Alta (8.8) | 1.2% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found. | |
| Modificada | Alta (8.8) | 1.6% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found. | |
| Modificada | Media (5.4) | 0.54% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found. | |
| Modificada | Media (5.3) | 1.9% | — | HP Matrix Operating Environment | 15/2/2018 | 17/6/2026 | A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found. | |
| Modificada | Alta (8.8) | 3.1% | — | Citrix Netscaler | 1/2/2018 | 17/6/2026 | Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges. | |
| Modificada | Media (5.3) | 0.65% | — | Matrixssl | 22/1/2018 | 17/6/2026 | MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates. | |
| Modificada | Media (5.9) | 0.48% | — | Matrixssl | 9/1/2018 | 17/6/2026 | MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years. | |
| Modificada | Media (5.9) | 1.6% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 13/12/2017 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client… | |
| Modificada | Media (5.9) | 14% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 13/12/2017 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | MLM Forced Matrix Project MLM Forced Matrix | 13/12/2017 | 17/6/2026 | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | |
| Modificada | Alta (8.8) | 1.8% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag. | |
| Modificada | Media (6.1) | 0.60% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins. | |
| Modificada | Alta (7.5) | 2.2% | — | Squiz Matrix | 30/11/2017 | 17/6/2026 | An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed. | |
| Modificada | Alta (7.2) | 4.4% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.8) | 0.56% | — | Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+194 | 21/11/2017 | 17/6/2026 | Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege. | |
| Modificada | Alta (7.2) | 2.4% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 26/9/2017 | 17/6/2026 | A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build… | |
| Modificada | Alta (8.8) | 1.7% | — | Orion-soft Bitrix | 24/8/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) "by" parameter to admin/orion.extfeedbackform_efbf_forms.php. | |
| Modificada | Alta (8.8) | 0.44% | — | XENCitrix XenserverDebian Linux | 24/8/2017 | 17/6/2026 | arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref. |