Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Comtech H8 Heights Remote Gateway Firmware | 17/10/2019 | 17/6/2026 | Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field. | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Ic3000 Industrial Compute Gateway Firmware | 2/10/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly manages system resources. An attacker… | |
| Modificada | Crítica (9.6) | 1.1% | — | Siemens Ie/wsn-pa Link Wirelesshart Gateway Firmware | 13/9/2019 | 17/6/2026 | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful… | |
| Modificada | Alta (7.5) | 1.5% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 22/5/2019 | 17/6/2026 | A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23. | |
| Modificada | Alta (8.1) | 1.0% | — | Kunbus Pr100088 Modbus Gateway Firmware | 2/4/2019 | 17/6/2026 | An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) if the attacker is in an MITM position. | |
| Modificada | Media (5.9) | 2.3% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 22/2/2019 | 17/6/2026 | Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5… | |
| Modificada | Alta (7.2) | 0.59% | — | Kunbus Pr100088 Modbus Gateway Firmware | 12/2/2019 | 17/6/2026 | An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) through FTP. | |
| Modificada | Crítica (9.1) | 1.2% | — | Kunbus Pr100088 Modbus Gateway Firmware | 12/2/2019 | 17/6/2026 | Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166). | |
| Modificada | Crítica (9.8) | 1.2% | — | Kunbus Pr100088 Modbus Gateway Firmware | 12/2/2019 | 17/6/2026 | PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted. | |
| Modificada | Media (4.8) | 0.83% | — | Citrix Netscaler Gateway Firmware | 24/10/2018 | 17/6/2026 | Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | UI Airmax AC FirmwareUI Airmax M XM FirmwareUI Airmax M XW FirmwareUI Airmax M TI Firmware+8 | 5/9/2018 | 17/6/2026 | The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in… | |
| Modificada | Crítica (9.8) | 1.7% | — | ABB IP Gateway Firmware | 6/6/2018 | 17/6/2026 | In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access. | |
| Modificada | Crítica (9.8) | 2.5% | — | ABB IP Gateway Firmware | 6/6/2018 | 17/6/2026 | In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication. | |
| Modificada | Alta (8.8) | 0.66% | — | ABB IP Gateway Firmware | 6/6/2018 | 17/6/2026 | In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user. | |
| Modificada | Crítica (9.8) | 6.2% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 17/5/2018 | 17/6/2026 | The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.1) | 1.2% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface. | |
| Modificada | Alta (7.5) | 4.4% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 6/3/2018 | 17/6/2026 | Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request. | |
| Modificada | Crítica (9.8) | 4.1% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system. | |
| Modificada | Alta (7.5) | 2.3% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 6/3/2018 | 17/6/2026 | NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system. | |
| Modificada | Media (5.9) | 1.6% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 13/12/2017 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client… | |
| Modificada | Media (5.9) | 14% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 13/12/2017 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack. | |
| Modificada | Alta (7.2) | 2.4% | — | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 26/9/2017 | 17/6/2026 | A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build… | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Sophos Astaro Security Gateway Firmware | 19/9/2017 | 17/6/2026 | Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. | |
| Modificada | Crítica (9.8) | 1.4% | — | Cisco Residential Gateway Firmware | 24/7/2017 | 17/6/2026 | On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd,… | |
| Modificada | Crítica (9.8) | 4.2% | — | Cisco Residential Gateway Firmware | 24/7/2017 | 17/6/2026 | On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to the waitPingqry.cgi URI. The command output is visible at… |