Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 167 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

924 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Citrix MetaframeCitrix Metaframe Presentation ServerCitrix Presentation Server24/7/200616/6/2026
Citrix MetaFrame para XP 1.0 característica 1, excepto cuando funciona sobre Windows Server 2003, instala una llave de registro con un ACL no seguro, lo cual permite a usuarios remotos validos ganar privilegios.
ModificadaAlta (7.5)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos disparar un error SQL a través del parámetro page_name, posiblemente debido a una vulnerabilidad de inyección SQL.
ModificadaMedia (4.3)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro page_name con una etiqueta IMG que contiene una URI javascript en el atributo SRC.
ModificadaMedia (5)1.2%—Orbitcoders Orbitmatrix18/7/200616/6/2026
index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos obtener información sensible (esquemas parciales de la base de datos) a través de parámetros page_name modificados, lo cual refleja porciones de una consulta SQL en el resultado. NOTA: no está clara si la información tiene un objetivo-especifico. Si…
ModificadaMedia (5)1.9%—Bitrix Site Manager19/5/200616/6/2026
The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site.
ModificadaMedia (4.9)1.1%—Bitrix Site Manager19/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs.
ModificadaMedia (5)1.6%—Bitrix Site Manager19/5/200616/6/2026
Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has been referred to as "cross-site scripting," but that is inconsistent with the common use of the term.
ModificadaMedia (5)2.2%—Bitrix Site Manager19/5/200616/6/2026
Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
ModificadaAlta (7.5)3.6%💥 ExploitAdcentrix Censtore18/4/200616/6/2026
censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
ModificadaMedia (4.3)1.4%—Netrix X-site Manager23/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the affected program might be installation-dependent, but it has been…
ModificadaBaja (2.1)0.44%—Citrix Program Neighborhood Client20/12/200516/6/2026
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field.
ModificadaAlta (7.5)16%—Citrix ICA Program Neighborhood Client16/12/200516/6/2026
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.
ModificadaMedia (4.3)1.4%—Citrix Metaframe Secure Access ManagerCitrix Nfuse3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModificadaAlta (7.5)2.1%—Citrix Metaframe4/10/200516/6/2026
Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).
ModificadaMedia (5)1.4%—Bitrix Site Manager15/6/200516/6/2026
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.
ModificadaMedia (5)1.5%—Bitrix Site Manager15/6/200516/6/2026
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.
ModificadaBaja (2.1)0.37%—Citrix Metaframe Password Manager2/5/200516/6/2026
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
ModificadaAlta (7.5)1.3%—Citrix Metaframe Conferencing ManagerAI2/5/200516/6/2026
Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
ModificadaAlta (7.5)1.2%—Peersec Networks Matrixssl31/12/200416/6/2026
PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.
ModificadaMedia (5.8)0.79%—Peersec Networks Matrixssl31/12/200416/6/2026
PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms…
ModificadaAlta (7.2)1.1%💥 ExploitUltrix Dxterm20/12/200416/6/2026
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.
ModificadaAlta (7.5)3.8%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.
ModificadaMedia (5)1.2%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.
ModificadaMedia (5)1.8%—Matrix FTP ServerAI6/2/200416/6/2026
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.