Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
3271 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to… | |
| Modificada | Alta (7) | 0.24% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression… | |
| Analizada | Crítica (9.3) | 0.36% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before… | |
| Analizada | Crítica (9.5) | 1.3% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 28/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service | |
| Analizada | Crítica (9.5) | 1.1% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute… | |
| Aplazada | Alta (7.5) | 0.36% | — | Ciena Navigator Network Control SuiteAI | 25/9/2026 | 28/9/2026 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information. | |
| Pendiente de análisis | Media (6.1) | 0.30% | — | Netgate PfsenseAIPfblockerngAI | 25/9/2026 | 30/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | |
| Pendiente de análisis | Alta (8.5) | 1.0% | — | Netgate Pfsense PlusAINetgate Pfsense CEAI | 25/9/2026 | 30/9/2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write… | |
| Aplazada | Media (5.3) | 0.34% | — | DbgateAI | 24/9/2026 | 24/9/2026 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack… | |
| Aplazada | Media (5.3) | 0.24% | — | DbgateAI | 24/9/2026 | 25/9/2026 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection. The attack may be performed from remote. Upgrading to… | |
| Aplazada | Media (6.5) | 0.25% | — | Conekta Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. | |
| Aplazada | Media (6.5) | 0.19% | — | Payplus Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Analizada | Alta (7.5) | 0.26% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.3) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection… | |
| Analizada | Alta (7.4) | 0.25% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (6.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection… | |
| Analizada | Media (6.4) | 0.11% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and… | |
| Analizada | Baja (3.7) | 0.16% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 26/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.4) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. | |
| Analizada | Media (6.8) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| En análisis | Alta (7.4) | 0.50% | — | Watchguard Authpoint GatewayAI | 23/9/2026 | 24/9/2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | |
| Aplazada | Media (5.3) | 0.18% | — | Sumit Payment GatewayAI | 23/9/2026 | 24/9/2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | |
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. |