Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

427 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.4%—Citrix Xenapp11/6/202017/6/2026
Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.8)0.58%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
ModificadaAlta (7.8)0.57%💥 PoCCitrix Workspace APP8/6/202017/6/2026
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
ModificadaAlta (7.5)4.6%—Citrix Sharefile Storagezones Controller7/5/202017/6/2026
An arbitrary file write issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, which allows remote code execution. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud…
ModificadaAlta (7.5)27%💥 ExploitCitrix Sharefile Storagezones Controller7/5/202017/6/2026
An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be it on-premise or inside Citrix Cloud itself (both are…
ModificadaAlta (7.5)14%💥 PoCCitrix Sharefile Storagezones Controller7/5/202017/6/2026
In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike most CVEs, exploitability depends on the product version…
ModificadaMedia (5.9)0.59%—Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center16/3/202017/6/2026
Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.
ModificadaMedia (6.1)0.78%—Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center10/3/202017/6/2026
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
ModificadaMedia (5.4)1.5%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies that those cached pages would not…
ModificadaAlta (7.5)2.0%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization
ModificadaMedia (5.3)2.7%—Citrix Gateway Firmware6/3/202017/6/2026
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between the start and end points for a request…
ModificadaAlta (7.8)0.36%—Citrix Xenserver23/1/202016/6/2026
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.
ModificadaAlta (7.8)6.9%—Citrix ReceiverCitrix Xenapp Online10/1/202016/6/2026
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.
ModificadaAlta (7.5)3.6%—Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+12/1/202016/6/2026
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
ModificadaAlta (8.1)9.7%—Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+12/1/202016/6/2026
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware27/12/201912/8/2026
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
ModificadaCrítica (9.8)1.5%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway Firmware21/10/201917/6/2026
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass authentication to obtain appliance…
ModificadaAlta (8.8)1.3%—Citrix Application Delivery Management9/10/201917/6/2026
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
AnalizadaAlta (7.5)30%⚠ Explotación activa💥 ExploitCitrix Storefront Server29/8/201917/6/2026
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ModificadaAlta (8.8)49%—Citrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
AnalizadaAlta (8.8)74%⚠ Explotación activa💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
ModificadaCrítica (9.8)39%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
ModificadaCrítica (9.8)43%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
ModificadaCrítica (9.8)43%💥 ExploitCitrix Netscaler Sd-wanCitrix Sd-wan16/7/201917/6/2026
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).