VYPR

Vendor CVEs

Citrix Systems

All CVEs

410 total · sorted by risk
  • CVE-2023-3519CriKEVJul 19, 2023
    risk 0.93cvss 9.8epss 1.00

    Unauthenticated remote code execution

  • CVE-2019-19781CriKEVDec 27, 2019
    risk 0.93cvss 9.8epss 1.00

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

  • CVE-2023-4966CriKEVOct 10, 2023
    risk 0.90cvss 9.4epss 1.00

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2021-22941CriKEVSep 23, 2021
    risk 0.86cvss 9.8epss 0.54

    Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

  • CVE-2019-12989CriKEVJul 16, 2019
    risk 0.86cvss 9.8epss 0.94

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

  • CVE-2026-3055CriKEVMar 23, 2026
    risk 0.85cvss 9.8epss 0.84

    Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

  • CVE-2017-6316CriKEVJul 20, 2017
    risk 0.85cvss 9.8epss 0.73

    Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

  • CVE-2023-24489CriKEVJul 10, 2023
    risk 0.83cvss 9.8epss 0.95

    A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

  • CVE-2019-11634CriKEVMay 22, 2019
    risk 0.82cvss 9.8epss 0.08

    Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

  • CVE-2025-5777HigKEVJun 17, 2025
    risk 0.78cvss 7.5epss 1.00

    Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2019-12991HigKEVJul 16, 2019
    risk 0.78cvss 8.8epss 0.74

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

  • CVE-2025-7775CriKEVAug 26, 2025
    risk 0.77cvss 9.8epss 0.20

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler…

  • CVE-2025-6543CriKEVJun 25, 2025
    risk 0.76cvss 9.8epss 0.10

    Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2022-27518CriKEVDec 13, 2022
    risk 0.76cvss 9.8epss 0.07

    Unauthenticated remote arbitrary code execution

  • CVE-2023-6549HigKEVJan 17, 2024
    risk 0.70cvss 8.2epss 0.58

    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

  • CVE-2019-13608HigKEVAug 29, 2019
    risk 0.69cvss 7.5epss 0.30

    Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

  • CVE-2019-10883CriJun 3, 2019
    risk 0.69cvss 9.8epss 0.65

    Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.

  • CVE-2018-14007CriAug 15, 2018
    risk 0.68cvss 9.8epss 0.56

    Citrix XenServer 7.1 and newer allows Directory Traversal.

  • CVE-2019-12990CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.39

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.

  • CVE-2019-12988CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.43

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

  • CVE-2019-12987CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.43

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

  • CVE-2019-12986CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.40

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

  • CVE-2019-12985CriJul 16, 2019
    risk 0.67cvss 9.8epss 0.40

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

  • CVE-2018-10653CriMay 23, 2018
    risk 0.67cvss 9.8epss 0.07

    There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2024-8069HigKEVNov 12, 2024
    risk 0.65cvss 8.0epss 0.15

    Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

  • CVE-2020-8271CriNov 16, 2020
    risk 0.65cvss 9.8epss 0.11

    Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

  • CVE-2019-9548CriJun 5, 2019
    risk 0.65cvss 10.0epss 0.01

    Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.

  • CVE-2018-17445CriOct 23, 2018
    risk 0.65cvss 9.8epss 0.11

    A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

  • CVE-2015-7705CriAug 7, 2017
    risk 0.65cvss 9.8epss 0.12

    The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.

  • CVE-2025-7776CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.07

    Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it

  • CVE-2024-8068HigKEVNov 12, 2024
    risk 0.64cvss 8.0epss 0.01

    Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

  • CVE-2022-27510CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthorized access to Gateway user capabilities

  • CVE-2021-22891CriMay 27, 2021
    risk 0.64cvss 9.8epss 0.01

    A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller.

  • CVE-2020-8257CriDec 14, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks

  • CVE-2020-8212CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

  • CVE-2020-8211CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

  • CVE-2019-18225CriOct 21, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass…

  • CVE-2019-12292CriJun 24, 2019
    risk 0.64cvss 9.8epss 0.01

    Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.

  • CVE-2018-17448CriOct 23, 2018
    risk 0.64cvss 9.8epss 0.02

    An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

  • CVE-2018-17446CriOct 23, 2018
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

  • CVE-2018-10648CriMay 23, 2018
    risk 0.64cvss 9.8epss 0.01

    There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-7218CriMay 17, 2018
    risk 0.64cvss 9.8epss 0.06

    The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2018-6809CriMar 6, 2018
    risk 0.64cvss 9.8epss 0.04

    NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.

  • CVE-2016-9679CriJan 18, 2017
    risk 0.64cvss 9.8epss 0.03

    Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code by overwriting a function pointer.

  • CVE-2016-9678CriJan 18, 2017
    risk 0.64cvss 9.8epss 0.03

    Use-after-free vulnerability in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2016-9676CriJan 18, 2017
    risk 0.64cvss 9.8epss 0.04

    Buffer overflow in Citrix Provisioning Services before 7.12 allows attackers to execute arbitrary code via unspecified vectors.

  • CVE-2016-6493CriAug 19, 2016
    risk 0.64cvss 9.8epss 0.02

    Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.

  • CVE-2016-5302CriJun 13, 2016
    risk 0.64cvss 9.8epss 0.03

    Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

Page 1 of 9