Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

354 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.94%💥 PoCFortra Delivernow19/9/202317/6/2026
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
ModificadaMedia (5.5)0.16%—Dell Digital Delivery8/9/202317/6/2026
Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
ModificadaCrítica (9.8)15%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Xtended Services Platform6/9/202317/6/2026
A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This vulnerability is due to the method used to…
ModificadaCrítica (9.8)0.89%—Phpjabbers Food Delivery Script28/8/202317/6/2026
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
ModificadaCrítica (9.8)3.7%💥 ExploitPhpjabbers Food Delivery Script28/8/202317/6/2026
PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.
ModificadaCrítica (9.8)3.3%💥 ExploitPhpjabbers Food Delivery Script28/8/202317/6/2026
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.
ModificadaAlta (7.8)0.16%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+83/8/202317/6/2026
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability…
ModificadaMedia (5.4)0.45%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform3/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly…
ModificadaAlta (8)1.3%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Privilege Escalation to root administrator (nsroot)
ModificadaMedia (6.1)2.6%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/202317/6/2026
Reflected Cross-Site Scripting (XSS)
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/7/20235/8/2026
Unauthenticated remote code execution
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
ModificadaMedia (4.3)0.30%—Citrix Virtual Apps AND DesktopsCitrix Linux Virtual Delivery Agent10/7/202317/6/2026
Users with only access to launch VDA applications can launch an unauthorized desktop
ModificadaMedia (6.1)81%💥 ExploitCitrix GatewayCitrix Application Delivery Controller10/7/202317/6/2026
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
ModificadaAlta (7.5)1.1%—Citrix Application Delivery ControllerCitrix Gateway10/7/202317/6/2026
Arbitrary file read in Citrix ADC and Citrix Gateway
ModificadaMedia (4.8)0.44%—Byconsole Pickup | Delivery | Dine-in Date Time8/5/202317/6/2026
The Pickup | Delivery | Dine-in date time WordPress plugin through 1.0.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)0.18%—Wolt Delivery11/4/202317/6/2026
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaAlta (8.8)0.42%—Edgenexus Application Delivery Controller23/1/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)3.5%—Edgenexus Application Delivery Controller23/1/202317/6/2026
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via…
ModificadaAlta (8.6)0.86%—Cisco Broadworks Application Delivery Platform Device ManagementCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
ModificadaMedia (6.1)0.59%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Xtended Services Platform20/1/202317/6/2026
A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform, Cisco BroadWorks Application Server, and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of…
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
Orbitaley — Vulnerabilidades