Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.94% | 💥 PoC | Fortra Delivernow | 19/9/2023 | 17/6/2026 | SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information. | |
| Modificada | Media (5.5) | 0.16% | — | Dell Digital Delivery | 8/9/2023 | 17/6/2026 | Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS). | |
| Modificada | Crítica (9.8) | 15% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Xtended Services Platform | 6/9/2023 | 17/6/2026 | A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to… | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (5.4) | 0.45% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform | 3/8/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly… | |
| Modificada | Alta (8) | 1.3% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Privilege Escalation to root administrator (nsroot) | |
| Modificada | Media (6.1) | 2.6% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/7/2023 | 5/8/2026 | Unauthenticated remote code execution | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Media (4.3) | 0.30% | — | Citrix Virtual Apps AND DesktopsCitrix Linux Virtual Delivery Agent | 10/7/2023 | 17/6/2026 | Users with only access to launch VDA applications can launch an unauthorized desktop | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Citrix GatewayCitrix Application Delivery Controller | 10/7/2023 | 17/6/2026 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | |
| Modificada | Alta (7.5) | 1.1% | — | Citrix Application Delivery ControllerCitrix Gateway | 10/7/2023 | 17/6/2026 | Arbitrary file read in Citrix ADC and Citrix Gateway | |
| Modificada | Media (4.8) | 0.44% | — | Byconsole Pickup | Delivery | Dine-in Date Time | 8/5/2023 | 17/6/2026 | The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 0.18% | — | Wolt Delivery | 11/4/2023 | 17/6/2026 | Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary. | |
| Modificada | Alta (7.5) | 1.0% | — | Citrix Application Delivery ControllerCitrix Gateway | 26/1/2023 | 17/6/2026 | Unauthenticated denial of service | |
| Modificada | Media (6.5) | 0.99% | — | Citrix GatewayCitrix Application Delivery Controller | 26/1/2023 | 17/6/2026 | Authenticated denial of service | |
| Modificada | Alta (8.8) | 0.42% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 3.5% | — | Edgenexus Application Delivery Controller | 23/1/2023 | 17/6/2026 | The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via… | |
| Modificada | Alta (8.6) | 0.86% | — | Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform | 20/1/2023 | 17/6/2026 | A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Modificada | Media (6.1) | 0.59% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform | 20/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of… | |
| Modificada | Media (6.5) | 0.59% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 26/12/2022 | 17/6/2026 | In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update. | |
| Analizada | Crítica (9.8) | 6.7% | ⚠ Explotación activa💥 PoC | Citrix Application Delivery Controller FirmwareCitrix Gateway Firmware | 13/12/2022 | 17/6/2026 | Unauthenticated remote arbitrary code execution |