Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Citrix Netscaler Application Delivery Controller Firmware | 11/3/2014 | 17/6/2026 | Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to the "Virtual… | |
| Modificada | Alta (7.8) | 1.5% | — | Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery Controller | 4/10/2013 | 16/6/2026 | Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request. | |
| Modificada | Media (5.4) | 1.5% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/4/2013 | 16/6/2026 | Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors. | |
| Modificada | Media (6.5) | 2.0% | — | Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway | 25/6/2009 | 16/6/2026 | The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions. | |
| Modificada | Baja (2.1) | 0.44% | — | Citrix Edgesight FOR EndpointsCitrix Edgesight FOR NetscalerCitrix Edgesight FOR Presentation Server | 7/12/2007 | 16/6/2026 | Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information. | |
| Modificada | Media (5) | 1.1% | — | Citrix Netscaler | 30/11/2007 | 16/6/2026 | The web management interface in Citrix NetScaler 8.0 build 47.8 stores the device's primary IP address in a cookie, which might allow remote attackers to obtain sensitive network configuration information if this address is not the same as the address being used by the web interface. | |
| Modificada | Media (4.3) | 0.70% | — | Citrix Netscaler | 30/11/2007 | 16/6/2026 | The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-plaintext attack. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Citrix Netscaler | 20/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ws/generic_api_call.pl in Citrix NetScaler 8.0 build 47.8 allows remote attackers to inject arbitrary web script or HTML via the standalone parameter and other unspecified parameters. |