Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
427 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | |
| Modificada | Media (6.5) | 1.9% | — | Citrix Xenserver | 11/7/2019 | 17/6/2026 | The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame. | |
| Modificada | Crítica (9.8) | 1.5% | — | Citrix Appdna | 24/6/2019 | 17/6/2026 | Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control. | |
| Modificada | Crítica (10) | 1.5% | — | Citrix Application Delivery Management | 5/6/2019 | 17/6/2026 | Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control. | |
| Modificada | Crítica (9.1) | 2.6% | — | Citrix Xenmobile Server | 5/6/2019 | 17/6/2026 | An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device. | |
| Modificada | Crítica (9.8) | 65% | — | Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center | 3/6/2019 | 17/6/2026 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | |
| Analizada | Crítica (9.8) | 8.1% | ⚠ Explotación activa | Citrix ReceiverCitrix Workspace | 22/5/2019 | 12/8/2026 | Citrix Workspace App before 1904 for Windows has Incorrect Access Control. | |
| Modificada | Alta (7.5) | 1.5% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 22/5/2019 | 17/6/2026 | A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23. | |
| Modificada | Media (5.9) | 1.2% | — | Citrix Sharefile | 13/5/2019 | 17/6/2026 | Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using… | |
| Modificada | Alta (7.5) | 2.0% | — | Citrix Sharefile | 13/5/2019 | 17/6/2026 | Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required. | |
| Modificada | Media (5.9) | 0.58% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 8/5/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. | |
| Modificada | Media (5.9) | 2.3% | — | Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware | 22/2/2019 | 17/6/2026 | Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5… | |
| Modificada | Media (5.6) | 0.43% | — | XENCitrix XenserverDebian Linux | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation. | |
| Modificada | Alta (7.8) | 0.41% | — | XENDebian LinuxCitrix Xenserver | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones. | |
| Modificada | Alta (7.8) | 0.41% | — | XENDebian LinuxCitrix Xenserver | 8/12/2018 | 17/6/2026 | An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes. | |
| Modificada | Media (4.8) | 0.83% | — | Citrix Netscaler Gateway Firmware | 24/10/2018 | 17/6/2026 | Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. | |
| Modificada | Media (4.8) | 0.48% | — | Citrix Xenmobile Server | 24/10/2018 | 17/6/2026 | * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal… | |
| Modificada | Alta (7.8) | 2.9% | — | Citrix Xenmobile Server | 24/10/2018 | 17/6/2026 | * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor… | |
| Modificada | Crítica (9.8) | 2.2% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 1.9% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 2.0% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 11% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 3.6% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Media (4.3) | 1.1% | — | Citrix Sharefile Storagezones Controller | 26/9/2018 | 17/6/2026 | Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. |