VYPR

Vendor CVEs

Citrix Systems

All CVEs

410 total · sorted by risk
  • CVE-2016-2071CriFeb 17, 2016
    risk 0.64cvss 9.8epss 0.03

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

  • CVE-2023-24492CriJul 11, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.

  • CVE-2020-8193MedKEVJul 10, 2020
    risk 0.61cvss 6.5epss 0.88

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

  • CVE-2019-12992HigJul 16, 2019
    risk 0.61cvss 8.8epss 0.49

    Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

  • CVE-2009-3759HigOct 22, 2009
    risk 0.60cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to…

  • CVE-2024-6235HigJul 10, 2024
    risk 0.59cvss 8.8epss 0.21

    Sensitive information disclosure in NetScaler Console

  • CVE-2018-18571CriJun 5, 2019
    risk 0.59cvss 9.1epss 0.03

    An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.

  • CVE-2024-12284HigFeb 20, 2025
    risk 0.58cvss 8.8epss 0.13

    Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.

  • CVE-2021-44520HigApr 13, 2022
    risk 0.58cvss 8.8epss 0.06

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

  • CVE-2017-7219HigApr 13, 2017
    risk 0.58cvss 8.8epss 0.05

    A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.

  • CVE-2025-5349HigJun 17, 2025
    risk 0.57cvss 8.8epss 0.04

    Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway

  • CVE-2024-6148HigJul 10, 2024
    risk 0.57cvss 8.8epss 0.00

    Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

  • CVE-2021-44519HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.03

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

  • CVE-2020-8283HigDec 14, 2020
    risk 0.57cvss 8.8epss 0.03

    An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

  • CVE-2020-8273HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8.

  • CVE-2020-8270HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342

  • CVE-2020-8269HigNov 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

  • CVE-2020-8247HigSep 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before…

  • CVE-2020-8207HigJul 24, 2020
    risk 0.57cvss 8.8epss 0.02

    Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.

  • CVE-2020-8197HigJul 10, 2020
    risk 0.57cvss 8.8epss 0.02

    Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.

  • CVE-2020-8195MedKEVJul 10, 2020
    risk 0.57cvss 6.5epss 0.33

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

  • CVE-2019-17366HigOct 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.

  • CVE-2018-6186HigFeb 1, 2018
    risk 0.57cvss 8.8epss 0.03

    Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.

  • CVE-2017-15592HigOct 18, 2017
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.

  • CVE-2017-14316HigSep 12, 2017
    risk 0.57cvss 8.8epss 0.00

    A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memflags` parameter; the node is extracted using the `MEMF_get_node` macro. While…

  • CVE-2017-12137HigAug 24, 2017
    risk 0.57cvss 8.8epss 0.00

    arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

  • CVE-2017-12135HigAug 24, 2017
    risk 0.57cvss 8.8epss 0.00

    Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

  • CVE-2017-12134HigAug 24, 2017
    risk 0.57cvss 8.8epss 0.01

    The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block…

  • CVE-2016-9383HigJan 23, 2017
    risk 0.57cvss 8.8epss 0.01

    Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute arbitrary code on the host by leveraging broken emulation of bit test…

  • CVE-2016-9028HigOct 28, 2016
    risk 0.57cvss 8.8epss 0.02

    Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.

  • CVE-2016-6258HigAug 2, 2016
    risk 0.57cvss 8.8epss 0.00

    The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

  • CVE-2016-3710HigMay 11, 2016
    risk 0.57cvss 8.8epss 0.01

    The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

  • CVE-2013-3619HigJan 2, 2020
    risk 0.56cvss 8.1epss 0.10

    Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL…

  • CVE-2015-8555HigApr 13, 2016
    risk 0.56cvss 8.6epss 0.02

    Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspecified vectors.

  • CVE-2023-3466HigJul 19, 2023
    risk 0.54cvss 8.3epss 0.03

    Reflected Cross-Site Scripting (XSS)

  • CVE-2022-27513HigNov 8, 2022
    risk 0.54cvss 8.3epss 0.00

    Remote desktop takeover via phishing

  • CVE-2022-27511HigJun 16, 2022
    risk 0.54cvss 8.1epss 0.12

    Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.

  • CVE-2024-8535HigNov 12, 2024
    risk 0.53cvss 8.1epss 0.00

    Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the…

  • CVE-2024-8534HigNov 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy…

  • CVE-2023-4967HigOct 27, 2023
    risk 0.53cvss 8.2epss 0.01

    Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

  • CVE-2021-22927HigAug 5, 2021
    risk 0.53cvss 8.1epss 0.01

    A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacker to hijack a session.

  • CVE-2020-8209HigAug 17, 2020
    risk 0.53cvss 7.5epss 0.49

    Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

  • CVE-2018-10654HigMay 23, 2018
    risk 0.53cvss 8.1epss 0.01

    There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2015-7999HigApr 14, 2016
    risk 0.53cvss 8.1epss 0.02

    Multiple SQL injection vulnerabilities in the Administration Web UI servlets in Citrix Command Center before 5.1 Build 36.7 and 5.2 before Build 44.11 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2023-3467HigJul 19, 2023
    risk 0.52cvss 8.0epss 0.02

    Privilege Escalation to root administrator (nsroot)

  • CVE-2025-6759HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

  • CVE-2025-4879HigJun 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  • CVE-2025-0320HigJun 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows

  • CVE-2024-6677HigJul 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation in uberAgent

  • CVE-2024-6286HigJul 10, 2024
    risk 0.51cvss 7.8epss 0.00

    Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Page 2 of 9