Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 28% | 💥 Exploit | Citrix Access Gateway | 14/1/2011 | 16/6/2026 | The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers to execute arbitrary commands via shell metacharacters in… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability." | |
| Modificada | Media (4.3) | 14% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access… | |
| Modificada | Media (4.3) | 14% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability." | |
| Modificada | Media (5.8) | 13% | — | Microsoft Forefront Unified Access Gateway | 10/11/2010 | 16/6/2026 | Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability." | |
| Modificada | Media (6.8) | 4.8% | — | Aladdin Safenet Securewire Access GatewayCisco Adaptive Security ApplianceSonicwall E-class SSL VPNSonicwall SSL VPN+1 | 4/12/2009 | 16/6/2026 | Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that… | |
| Modificada | Media (6.5) | 2.0% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/6/2009 | 16/6/2026 | The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions. | |
| Modificada | Alta (7.8) | 1.6% | — | Cisco Physical Access Gateway | 25/6/2009 | 16/6/2026 | Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets. | |
| Modificada | Alta (10) | 2.7% | — | Citrix Access Gateway | 3/6/2008 | 16/6/2026 | Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | Citrix Access Gateway | 5/11/2007 | 16/6/2026 | The web portal interface in Citrix Access Gateway (aka Citrix Advanced Access Control) before Advanced Edition 4.5 HF1 places a session ID in the URL, which allows context-dependent attackers to hijack sessions by reading "residual information", including the a referer log, browser history, or browser cache. | |
| Modificada | Alta (9.3) | 4.2% | — | Citrix Access GatewayCitrix Endpoint Analysis ClientMozilla Firefox | 26/7/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before 4.5.0.0 in Citrix Access Gateway Standard Edition before 4.5.5 and… | |
| Modificada | Alta (7.6) | 2.5% | — | Citrix Access Gateway | 26/7/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the web-based administration console in Citrix Access Gateway before firmware 4.5.5 allows remote attackers to perform certain configuration changes as administrators. | |
| Modificada | Media (6.8) | 1.3% | — | Citrix Access Gateway | 26/7/2007 | 16/6/2026 | Citrix Access Gateway Advanced Edition before firmware 4.5.5 allows attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors. | |
| Modificada | Media (6.8) | 2.2% | — | Citrix Access Gateway | 26/7/2007 | 16/6/2026 | Unspecified vulnerability in the client components in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | Citrix Access Gateway | 25/7/2007 | 16/6/2026 | The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute arbitrary programs onto a client system. | |
| Modificada | Media (6.5) | 1.5% | — | Citrix Access Gateway | 15/12/2006 | 16/6/2026 | Unspecified vulnerability in Citrix Advanced Access Control (AAC) Option 4.0, and Access Gateway 4.2 with Advanced Access Control 4.2, before 20061114, when the Browser-Only access feature is enabled, allows remote authenticated users to bypass access policies via a certain login method, a different issue than… | |
| Modificada | Media (6) | 1.5% | — | Citrix Access Gateway | 15/12/2006 | 16/6/2026 | Unspecified vulnerability in Citrix Access Gateway 4.5 Advanced Edition, and 4.2 with Advanced Access Control (AAC) 4.2, when deployed on the Access Gateway appliance 4.2 through 4.2.2 allows remote authenticated users to "gain access to data" and obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.1) | 3.8% | — | Citrix Access Gateway | 19/9/2006 | 16/6/2026 | Unspecified vulnerability in Citrix Access Gateway with Advanced Access Control (AAC) 4.2 before 20060914, when AAC is configured to use LDAP authentication, allows remote attackers to bypass authentication via unknown vectors. |