Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco IOSCisco Cgr1000 FirmwareCisco Ic3000 Industrial Compute Gateway Firmware | 24/3/2021 | 17/6/2026 | A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, remote attacker to cause a denial of service (DoS)… | |
| Modificada | Alta (8.8) | 2.7% | — | Emerson Wireless 1420 Gateway Firmware | 10/3/2021 | 17/6/2026 | Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application. | |
| Modificada | Media (6.1) | 0.97% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 10/7/2020 | 17/6/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS). | |
| Modificada | Alta (8.8) | 1.8% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 10/7/2020 | 17/6/2026 | Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands. | |
| Analizada | Media (4.3) | 26% | ⚠ Explotación activa | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 10/7/2020 | 17/6/2026 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. | |
| Analizada | Media (6.5) | 33% | ⚠ Explotación activa | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop+1 | 10/7/2020 | 17/6/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. | |
| Modificada | Media (6.5) | 11% | 💥 Exploit | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 10/7/2020 | 17/6/2026 | Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download. | |
| Analizada | Media (6.5) | 88% | ⚠ Explotación activa💥 Exploit | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 10/7/2020 | 17/6/2026 | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints. | |
| Modificada | Media (6.1) | 26% | 💥 Exploit | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop | 10/7/2020 | 17/6/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 1.2% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 10/7/2020 | 17/6/2026 | Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation. | |
| Modificada | Alta (7.5) | 1.9% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 10/7/2020 | 17/6/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack. | |
| Modificada | Crítica (9.8) | 1.3% | — | Farsite Farlinx X25 Gateway Firmware | 1/6/2020 | 17/6/2026 | FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php. | |
| Modificada | Media (5.3) | 1.3% | — | Farsite Farlinx X25 Gateway Firmware | 1/6/2020 | 17/6/2026 | FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature. | |
| Modificada | Crítica (9.8) | 2.5% | — | Farsite Farlinx X25 Gateway Firmware | 1/6/2020 | 17/6/2026 | FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php. | |
| Modificada | Alta (7.2) | 3.8% | — | Gira Tks-ip-gateway Firmware | 7/5/2020 | 17/6/2026 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to authenticated remote code execution via the backup functionality of the web frontend. This can be combined with CVE-2020-10794 for remote root access. | |
| Modificada | Crítica (9.8) | 1.4% | — | Gira Tks-ip-gateway Firmware | 7/5/2020 | 17/6/2026 | Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access. | |
| Modificada | Media (5.4) | 1.5% | — | Citrix Gateway Firmware | 6/3/2020 | 17/6/2026 | Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not… | |
| Modificada | Alta (7.5) | 2.0% | — | Citrix Gateway Firmware | 6/3/2020 | 17/6/2026 | Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization | |
| Modificada | Media (5.3) | 2.7% | — | Citrix Gateway Firmware | 6/3/2020 | 17/6/2026 | Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request… | |
| Modificada | Crítica (9.8) | 0.59% | — | Miele XGW 3000 Zigbee Gateway Firmware | 24/2/2020 | 17/6/2026 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480. | |
| Modificada | Alta (8.8) | 0.36% | — | Miele XGW 3000 Zigbee Gateway Firmware | 24/2/2020 | 17/6/2026 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection. | |
| Modificada | Media (4.9) | 1.0% | — | Kunbus Pr100088 Modbus Gateway Firmware | 7/1/2020 | 17/6/2026 | An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release R02 (or Software Version 1.1.13166). | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 27/12/2019 | 12/8/2026 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal. | |
| Modificada | Crítica (9.8) | 1.5% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware | 21/10/2019 | 17/6/2026 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance… |