Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 1.5% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware | 7/11/2014 | 17/6/2026 | Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors. | |
| Modificada | Media (5) | 1.7% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery Controller | 16/7/2014 | 17/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie. | |
| Modificada | Media (4.3) | 1.7% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 16/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 2/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 1.1% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller | 1/5/2014 | 17/6/2026 | Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation. | |
| Modificada | Alta (10) | 1.9% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway | 1/5/2014 | 17/6/2026 | Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors. | |
| Modificada | Alta (7.1) | 1.4% | — | Moxa Oncell Gateway FirmwareMoxa Oncell Gateway G3111Moxa Oncell Gateway G3151Moxa Oncell Gateway G3211+1 | 9/8/2013 | 16/6/2026 | Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, which makes it easier for remote attackers to obtain access by leveraging knowledge of a key from a product installation elsewhere. | |
| Modificada | Alta (10) | 2.3% | — | Turck Bl20 Programmable GatewayTurck Bl67 Programmable GatewayTurck Bl20 Programmable Gateway FirmwareTurck Bl67 Programmable Gateway Firmware | 23/5/2013 | 16/6/2026 | TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session. | |
| Modificada | Media (5.4) | 1.5% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/4/2013 | 16/6/2026 | Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors. | |
| Modificada | Media (4.3) | 0.94% | — | Cisco Spa8000 8-port IP Telephony Gateway FirmwareCisco Spa8000 8-port IP Telephony GatewayCisco Spa8800 8-port IP Telephony Gateway FirmwareCisco Spa8800 IP Telephony Gateway+14 | 13/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via the FROM field of an INVITE message, aka Bug IDs CSCtr27277,… | |
| Modificada | Media (5) | 1.2% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface… | |
| Modificada | Media (6.4) | 1.2% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable… | |
| Modificada | Alta (8.5) | 2.9% | — | Cisco Unified Videoconferencing System 5110 FirmwareCisco Unified Videoconferencing System 5115 FirmwareCisco Unified Videoconferencing System 5110Cisco Unified Videoconferencing System 5115+10 | 22/11/2010 | 16/6/2026 | goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified… | |
| Modificada | Media (6.5) | 2.0% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/6/2009 | 16/6/2026 | The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions. |