Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.59% | — | Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center | 16/3/2020 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation. | |
| Modificada | Media (6.1) | 0.78% | — | Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center | 10/3/2020 | 17/6/2026 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. | |
| Modificada | Alta (7.5) | 3.6% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312. | |
| Modificada | Alta (8.1) | 9.7% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon. | |
| Modificada | Alta (8.8) | 49% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). | |
| Analizada | Alta (8.8) | 74% | ⚠ Explotación activa | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). | |
| Modificada | Crítica (9.8) | 39% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. | |
| Modificada | Crítica (9.8) | 43% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). | |
| Modificada | Crítica (9.8) | 43% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). | |
| Modificada | Crítica (9.8) | 40% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). | |
| Modificada | Crítica (9.8) | 40% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 16/7/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). | |
| Modificada | Crítica (9.8) | 65% | — | Citrix Sd-wan CenterCitrix Netscaler Sd-wan Center | 3/6/2019 | 17/6/2026 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. | |
| Modificada | Media (5.9) | 0.58% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 8/5/2019 | 17/6/2026 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. | |
| Modificada | Crítica (9.8) | 2.2% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 1.9% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 2.0% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Crítica (9.8) | 11% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 3.6% | — | Citrix Netscaler Sd-wanCitrix Sd-wan | 23/10/2018 | 17/6/2026 | A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | |
| Modificada | Alta (7.5) | 2.8% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler GatewayCitrix Netscaler Sd-wan | 1/3/2018 | 17/6/2026 | Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN Optimization Edition 9.3.0 allows remote… | |
| Analizada | Crítica (9.8) | 73% | ⚠ Explotación activa | Citrix Netscaler Sd-wan | 20/7/2017 | 17/6/2026 | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID. |