Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

427 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.88%—Citrix Secure Access Client11/7/202317/6/2026
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
ModificadaAlta (7.8)0.20%—Citrix Secure Access Client11/7/202317/6/2026
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
ModificadaMedia (4.3)0.30%—Citrix Virtual Apps AND DesktopsCitrix Linux Virtual Delivery Agent10/7/202317/6/2026
Users with only access to launch VDA applications can launch an unauthorized desktop
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitCitrix Sharefile Storage Zones Controller10/7/202317/6/2026
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
ModificadaMedia (6.1)81%💥 ExploitCitrix GatewayCitrix Application Delivery Controller10/7/202317/6/2026
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
ModificadaAlta (7.5)1.1%—Citrix Application Delivery ControllerCitrix Gateway10/7/202317/6/2026
Arbitrary file read in Citrix ADC and Citrix Gateway
ModificadaMedia (5.5)0.18%—Citrix Workspace10/7/202317/6/2026
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
ModificadaAlta (7.8)0.22%—Citrix Workspace16/2/202317/6/2026
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app.
ModificadaMedia (5.5)0.26%—Citrix Workspace16/2/202317/6/2026
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
ModificadaAlta (7.8)0.27%—Citrix Virtual Apps AND Desktops16/2/202317/6/2026
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA.
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaCrítica (9.8)0.64%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
User login brute force protection functionality bypass
ModificadaCrítica (9.6)0.29%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Remote desktop takeover via phishing
ModificadaCrítica (9.8)1.1%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
Unauthorized access to Gateway user capabilities
ModificadaMedia (6.1)0.52%—Citrix GatewayCitrix Application Delivery Controller Firmware28/7/202217/6/2026
Unauthenticated redirection to a malicious website
ModificadaMedia (5.3)0.98%—Citrix Application Delivery Management16/6/202217/6/2026
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
ModificadaAlta (8.1)12%—Citrix Application Delivery Management16/6/202217/6/2026
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.
ModificadaAlta (7.1)0.18%—Citrix Gateway Plug-in26/5/202217/6/2026
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
ModificadaAlta (8.8)2.8%—Citrix Xenmobile Server19/4/202217/6/2026
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
ModificadaBaja (2.7)0.66%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+1013/4/202217/6/2026
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
ModificadaMedia (6.1)0.53%—Citrix Sd-wan 110 FirmwareCitrix Sd-wan 210 FirmwareCitrix Sd-wan 400 FirmwareCitrix Sd-wan 410 Firmware+813/4/202217/6/2026
Reflected cross site scripting (XSS)
ModificadaMedia (6.1)0.48%—Citrix Storefront Server13/4/202217/6/2026
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
Orbitaley — Vulnerabilidades