Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

3271 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to…
ModificadaAlta (7)0.24%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression…
AnalizadaCrítica (9.3)0.36%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before…
AnalizadaCrítica (9.5)1.3%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202628/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
AnalizadaCrítica (9.5)1.1%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute…
AplazadaAlta (7.5)0.36%—Ciena Navigator Network Control SuiteAI25/9/202628/9/2026
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
Pendiente de análisisMedia (6.1)0.30%—Netgate PfsenseAIPfblockerngAI25/9/202630/9/2026
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
Pendiente de análisisAlta (8.5)1.0%—Netgate Pfsense PlusAINetgate Pfsense CEAI25/9/202630/9/2026
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write…
AplazadaMedia (5.3)0.34%—DbgateAI24/9/202624/9/2026
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack…
AplazadaMedia (5.3)0.24%—DbgateAI24/9/202625/9/2026
A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection. The attack may be performed from remote. Upgrading to…
AplazadaMedia (6.5)0.25%—Conekta Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.
AplazadaMedia (6.5)0.19%—Payplus Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
AnalizadaAlta (7.5)0.26%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.3)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection…
AnalizadaAlta (7.4)0.25%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (6.8)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection…
AnalizadaMedia (6.4)0.11%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and…
AnalizadaBaja (3.7)0.16%—Dell Policy Manager FOR Secure Connect Gateway23/9/202626/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (5.4)0.14%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.
AnalizadaMedia (6.8)0.21%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
En análisisAlta (7.4)0.50%—Watchguard Authpoint GatewayAI23/9/202624/9/2026
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
AplazadaMedia (5.3)0.18%—Sumit Payment GatewayAI23/9/202624/9/2026
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
AplazadaAlta (8.6)0.27%—Jet-form-builder-stripe-gatewayAI23/9/202623/9/2026
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
Orbitaley — Vulnerabilidades