Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.64% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | User login brute force protection functionality bypass | |
| Modificada | Crítica (9.6) | 0.29% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Remote desktop takeover via phishing | |
| Modificada | Crítica (9.8) | 1.1% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 8/11/2022 | 17/6/2026 | Unauthorized access to Gateway user capabilities | |
| Modificada | Media (6.1) | 0.52% | — | Citrix GatewayCitrix Application Delivery Controller Firmware | 28/7/2022 | 17/6/2026 | Unauthenticated redirection to a malicious website | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Collect AND Deliver Interface FOR Woocommerce Project Collect AND Deliver Interface FOR Woocommerce | 17/7/2022 | 17/6/2026 | The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.59% | — | Floristone Flower Delivery | 27/6/2022 | 17/6/2026 | The Flower Delivery by Florist One WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setups) | |
| Modificada | Media (5.3) | 0.98% | — | Citrix Application Delivery Management | 16/6/2022 | 17/6/2026 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | |
| Modificada | Alta (8.1) | 12% | — | Citrix Application Delivery Management | 16/6/2022 | 17/6/2026 | Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted. | |
| Modificada | Media (4.8) | 0.48% | — | F5 Traffix Signaling Delivery Controller | 5/5/2022 | 17/6/2026 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software… | |
| Modificada | Media (4.8) | 0.48% | — | F5 Traffix Signaling Delivery Controller | 5/5/2022 | 17/6/2026 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note:… | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Sd-wan | 7/12/2021 | 17/6/2026 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (7.5) | 0.92% | — | Citrix Application Delivery Controller FirmwareCitrix Gateway | 7/12/2021 | 17/6/2026 | A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication. | |
| Modificada | Alta (8.1) | 0.82% | — | Puppet Continuous Delivery | 18/11/2021 | 17/6/2026 | A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0 | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Alta (8.1) | 0.84% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 5/8/2021 | 17/6/2026 | A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session. | |
| Modificada | Media (6.5) | 0.92% | — | Citrix Application Delivery ManagementCitrix Gateway | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a phishing attack through a SAML authentication… | |
| Modificada | Alta (7.5) | 0.94% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 5/8/2021 | 17/6/2026 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to the limited available disk space on the… | |
| Modificada | Media (6.1) | 1.1% | — | Ec-cube Delivery Slip NumberEc-cube Delivery Slip Number CSV Bulk RegistrationEc-cube Delivery Slip Number Mail | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1.0.8 and earlier) allows remote attackers to inject an arbitrary… | |
| Modificada | Media (6.5) | 3.0% | 💥 PoC | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller Firmware | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or Citrix Gateway must be configured as a… | |
| Modificada | Media (6.5) | 0.42% | — | Citrix GatewayCitrix Netscaler GatewayCitrix Application Delivery Controller FirmwareCitrix Sd-wan Wanop | 16/6/2021 | 17/6/2026 | Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from… | |
| Modificada | Alta (8.8) | 1.4% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 18/9/2020 | 17/6/2026 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1… | |
| Modificada | Alta (7.5) | 1.6% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler GatewayCitrix Sd-wan Wanop | 18/9/2020 | 17/6/2026 | Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1… | |
| Modificada | Media (6.1) | 0.93% | — | Citrix Application Delivery Controller FirmwareCitrix GatewayCitrix Netscaler Gateway | 18/9/2020 | 17/6/2026 | Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a,… | |
| Modificada | Media (5.5) | 0.31% | — | Puppet Continuous Delivery | 18/9/2020 | 17/6/2026 | Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1. |