Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware22/5/201917/6/2026
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.
ModificadaMedia (5.9)2.3%—Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware22/2/201917/6/2026
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5…
ModificadaMedia (6.1)1.2%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.
ModificadaAlta (7.5)4.4%—Citrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware6/3/201817/6/2026
Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.
ModificadaCrítica (9.8)4.1%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.
ModificadaAlta (7.5)2.3%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware6/3/201817/6/2026
NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.
ModificadaMedia (5.9)3.2%—Citrix Netscaler Application Delivery Controller Firmware8/2/201717/6/2026
Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging a reused nonce in a session and a…
ModificadaAlta (8.8)1.8%—Citrix Netscaler Application Delivery Controller Firmware28/10/201617/6/2026
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
ModificadaMedia (5)1.0%—Citrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Gateway FirmwareCitrix Netscaler Application Delivery Controller Firmware17/11/201517/6/2026
The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows attackers to obtain sensitive information via unspecified…
ModificadaMedia (4.3)1.00%—Citrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/11/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow remote…
ModificadaMedia (5)1.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Service Delivery Appliance Service VMCitrix Netscaler Gateway Firmware17/11/201517/6/2026
The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers to obtain credentials via the browser cache.
ModificadaMedia (4.3)1.4%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attackers to inject arbitrary web script or HTML via unspecified…
ModificadaAlta (10)3.2%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware17/9/201517/6/2026
Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the…
ModificadaAlta (9)4.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware16/7/201517/6/2026
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to…
ModificadaAlta (7.8)2.0%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware12/5/201517/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors.
ModificadaMedia (4.9)1.5%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Gateway Firmware7/11/201417/6/2026
Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5.50.10 before 10.5-52.11, 10.1.122.17 before 10.1-129.11, and 10.1-120.1316.e before 10.1-129.1105.e, when using unspecified configurations, allows remote authenticated users to access "network resources" of other users via unknown vectors.
ModificadaAlta (7.5)16%—Citrix Netscaler Application Delivery Controller Firmware21/10/201417/6/2026
Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5)1.7%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery Controller16/7/201417/6/2026
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.
ModificadaMedia (4.3)1.7%—Citrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway FirmwareCitrix Netscaler Access Gateway16/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)1.1%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Access GatewayCitrix Netscaler Application Delivery Controller1/5/201417/6/2026
Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.
ModificadaAlta (10)1.9%—Citrix Netscaler Access Gateway FirmwareCitrix Netscaler Application Delivery Controller FirmwareCitrix Netscaler Application Delivery ControllerCitrix Netscaler Access Gateway1/5/201417/6/2026
Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.
ModificadaMedia (5)1.6%—Citrix Netscaler Application Delivery Controller Firmware11/3/201417/6/2026
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.
ModificadaMedia (4.3)1.5%—Citrix Netscaler Application Delivery Controller Firmware11/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.87%—Citrix Netscaler Application Delivery Controller Firmware11/3/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (10)1.6%—Citrix Netscaler Application Delivery Controller Firmware11/3/201417/6/2026
Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors.