VYPR

Vendor CVEs

Citrix Systems

All CVEs

410 total · sorted by risk
  • CVE-2018-10652HigMay 23, 2018
    risk 0.49cvss 7.5epss 0.01

    There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

  • CVE-2018-6810HigMar 6, 2018
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.

  • CVE-2018-6808HigMar 6, 2018
    risk 0.49cvss 7.5epss 0.02

    NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.

  • CVE-2018-5314HigMar 1, 2018
    risk 0.49cvss 7.5epss 0.03

    Command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13; and the NetScaler Load Balancing instance distributed with NetScaler SD-WAN/CloudBridge 4000, 4100, 5000 and 5100 WAN…

  • CVE-2017-9231HigJun 16, 2017
    risk 0.49cvss 7.5epss 0.02

    XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

  • CVE-2016-9637HigFeb 17, 2017
    risk 0.49cvss 7.5epss 0.00

    The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

  • CVE-2016-9381HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.00

    Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.

  • CVE-2016-9380HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.00

    The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.

  • CVE-2016-9680HigJan 18, 2017
    risk 0.49cvss 7.5epss 0.02

    Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.

  • CVE-2016-6273HigOct 7, 2016
    risk 0.49cvss 7.5epss 0.02

    The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of…

  • CVE-2016-4810HigJun 1, 2016
    risk 0.49cvss 7.5epss 0.01

    Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.

  • CVE-2023-6548MedKEVJan 17, 2024
    risk 0.48cvss 5.5epss 0.03

    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

  • CVE-2024-7890HigSep 11, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  • CVE-2024-7889HigSep 11, 2024
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

  • CVE-2022-26151HigApr 13, 2022
    risk 0.47cvss 7.2epss 0.08

    Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

  • CVE-2017-14602HigSep 26, 2017
    risk 0.47cvss 7.2epss 0.02

    A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and…

  • CVE-2016-9111MedNov 7, 2016
    risk 0.47cvss 6.8epss 0.02

    Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue,…

  • CVE-2023-24488MedJul 10, 2023
    risk 0.46cvss 6.1epss 0.81

    Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

  • CVE-2022-21827HigMay 26, 2022
    risk 0.46cvss 7.1epss 0.00

    An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as…

  • CVE-2019-18910MedNov 22, 2019
    risk 0.44cvss 6.8epss 0.01

    The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

  • CVE-2020-8194MedJul 10, 2020
    risk 0.43cvss 6.5epss 0.11

    Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download.

  • CVE-2024-2049MedMar 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

  • CVE-2022-27507MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Authenticated denial of service

  • CVE-2019-18177MedDec 26, 2022
    risk 0.42cvss 6.5epss 0.01

    In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.

  • CVE-2021-22920MedAug 5, 2021
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, could lead to a…

  • CVE-2020-8300MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.03

    Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. Note that Citrix ADC or…

  • CVE-2020-8299MedJun 16, 2021
    risk 0.42cvss 6.5epss 0.00

    Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a…

  • CVE-2020-8274MedJan 6, 2021
    risk 0.42cvss 6.5epss 0.02

    Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat…

  • CVE-2020-8200MedSep 18, 2020
    risk 0.42cvss 6.5epss 0.01

    Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.

  • CVE-2020-8196MedKEVJul 10, 2020
    risk 0.42cvss 4.3epss 0.26

    Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privileged users.

  • CVE-2014-3798MedJul 11, 2019
    risk 0.42cvss 6.5epss 0.02

    The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.

  • CVE-2017-17382MedDec 13, 2017
    risk 0.42cvss 5.9epss 0.14

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA…

  • CVE-2017-14318MedSep 12, 2017
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It checks to see if the calling domain is the owner of the page that is to be operated on. If it is not, the owner's grant table is…

  • CVE-2017-12855MedAug 15, 2017
    risk 0.42cvss 6.5epss 0.00

    Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some…

  • CVE-2017-5572MedJan 30, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.

  • CVE-2009-2213MedJun 25, 2009
    risk 0.42cvss 6.5epss 0.02

    The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass…

  • CVE-2023-5914MedJan 17, 2024
    risk 0.41cvss 5.4epss 0.73

      Cross-site scripting (XSS)

  • CVE-2023-24490MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.00

    Users with only access to launch VDA applications can launch an unauthorized desktop

  • CVE-2023-24487MedJul 10, 2023
    risk 0.41cvss 6.3epss 0.01

    Arbitrary file read in Citrix ADC and Citrix Gateway 

  • CVE-2020-8191MedJul 10, 2020
    risk 0.41cvss 6.1epss 0.26

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

  • CVE-2016-1571MedJan 22, 2016
    risk 0.41cvss 6.3epss 0.01

    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID…

  • CVE-2025-12101MedNov 11, 2025
    risk 0.40cvss epss 0.25

    Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2025-1223MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.00

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

  • CVE-2025-1222MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.00

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

  • CVE-2024-42423MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and…

  • CVE-2024-6149MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

  • CVE-2024-5492MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

  • CVE-2022-27509MedJul 28, 2022
    risk 0.40cvss 6.1epss 0.00

    Unauthenticated redirection to a malicious website

  • CVE-2022-27505MedApr 13, 2022
    risk 0.40cvss 6.1epss 0.01

    Reflected cross site scripting (XSS)

  • CVE-2022-27503MedApr 13, 2022
    risk 0.40cvss 6.1epss 0.00

    Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

Page 4 of 9