Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

427 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.1)1.1%—Citrix Sharefile Storagezones Controller26/9/201817/6/2026
Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal.
ModificadaCrítica (9.8)56%—Citrix Xenserver15/8/201817/6/2026
Citrix XenServer 7.1 and newer allows Directory Traversal.
ModificadaCrítica (9.9)4.4%—QemuCitrix XenserverRedhat OpenstackDebian Linux+527/7/201817/6/2026
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU…
ModificadaCrítica (9.9)3.6%—QemuCitrix XenserverRedhat OpenstackDebian Linux+627/7/201817/6/2026
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary…
ModificadaCrítica (9.1)3.6%—QemuCitrix XenserverRedhat OpenstackDebian Linux+63/7/201817/6/2026
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute…
ModificadaMedia (5.6)0.63%—Intel Core I3Intel Core I5Intel Core I7Intel Core M+1021/6/201817/6/2026
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.
ModificadaAlta (8.1)1.2%—Citrix Xenmobile Server23/5/201817/6/2026
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
ModificadaCrítica (9.8)6.8%💥 ExploitCitrix Xenmobile Server23/5/201817/6/2026
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
ModificadaAlta (7.5)1.2%—Citrix Xenmobile Server23/5/201817/6/2026
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
ModificadaMedia (6.1)0.73%—Citrix Xenmobile Server23/5/201817/6/2026
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
ModificadaAlta (7.8)0.82%—Citrix Xenmobile Server23/5/201817/6/2026
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
ModificadaMedia (6.1)0.67%—Citrix Xenmobile Server23/5/201817/6/2026
There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.
ModificadaCrítica (9.8)1.2%—Citrix Xenmobile Server23/5/201817/6/2026
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
ModificadaCrítica (9.8)6.2%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/5/201817/6/2026
The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.8)18%💥 ExploitDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+78/5/201817/6/2026
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example)…
ModificadaMedia (6.1)1.2%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.
ModificadaAlta (7.5)4.4%—Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware6/3/201817/6/2026
Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.
ModificadaCrítica (9.8)4.1%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.
ModificadaAlta (7.5)2.3%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
ModificadaAlta (7.8)0.39%—Gemalto Safenet Authentication Service FOR Citrix WEB Interface Agent2/3/201817/6/2026
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
ModificadaAlta (7.5)2.8%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler GatewayCitrix Netscaler Sd-wan1/3/201817/6/2026
Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote…
ModificadaAlta (8.8)3.1%—Citrix Netscaler1/2/201817/6/2026
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.
ModificadaMedia (5.9)1.6%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware13/12/201717/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client…
ModificadaMedia (5.9)14%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware13/12/201717/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
ModificadaAlta (7.2)2.4%—Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware26/9/201717/6/2026
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build…
Orbitaley — Vulnerabilidades