VYPR

NetScaler ADC

by Citrix Systems

CVEs (29)

  • CVE-2024-5492MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

  • CVE-2018-6811MedMar 6, 2018
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.

  • CVE-2017-5933MedFeb 8, 2017
    risk 0.39cvss 5.9epss 0.03

    Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging…

  • CVE-2026-8655CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is…

  • CVE-2026-13474HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

  • CVE-2026-10817HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler

  • CVE-2026-10816HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled

  • CVE-2015-5538Sep 17, 2015
    risk 0.00cvss —epss 0.03

    Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the…

  • CVE-2014-4347Jul 16, 2014
    risk 0.00cvss —epss 0.02

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie.

Page 2 of 2