Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.18% | — | Citrix Gateway Plug-in | 26/5/2022 | 17/6/2026 | An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM. | |
| Modificada | Alta (7.5) | 1.3% | — | Citrix Gateway Plug-in | 14/12/2020 | 17/6/2026 | Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows an attacker to modify arbitrary files. | |
| Modificada | Crítica (9.8) | 1.7% | — | Citrix Gateway Plug-in | 14/12/2020 | 17/6/2026 | Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks | |
| Modificada | Alta (7.8) | 0.41% | — | Citrix Gateway Plug-in FOR Linux | 10/7/2020 | 17/6/2026 | Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root. | |
| Analizada | Media (6.5) | 33% | ⚠ Explotación activa | Citrix Application Delivery Controller FirmwareCitrix Netscaler Gateway FirmwareCitrix Gateway FirmwareCitrix Sd-wan Wanop+1 | 10/7/2020 | 17/6/2026 | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users. | |
| Modificada | Media (6.8) | 4.0% | — | Citrix Access Gateway Plug-in | 12/8/2014 | 16/6/2026 | Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a crafted Content-Length HTTP header, which triggers a heap-based… | |
| Modificada | Alta (9.3) | 15% | — | Citrix Access Gateway Plug-in | 18/6/2014 | 16/6/2026 | Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header. |