VYPR

Vendor CVEs

Citrix Systems

All CVEs

423 total · sorted by risk
  • CVE-2020-8191MedJul 10, 2020
    risk 0.41cvss 6.1epss 0.26

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

  • CVE-2016-1571MedJan 22, 2016
    risk 0.41cvss 6.3epss 0.01

    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address in an INVVPID…

  • CVE-2025-12101MedNov 11, 2025
    risk 0.40cvss —epss 0.25

    Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2025-1223MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.00

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

  • CVE-2025-1222MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.00

    An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac

  • CVE-2024-42423MedSep 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and…

  • CVE-2024-6149MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

  • CVE-2024-5492MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

  • CVE-2022-27509MedJul 28, 2022
    risk 0.40cvss 6.1epss 0.01

    Unauthenticated redirection to a malicious website

  • CVE-2022-27505MedApr 13, 2022
    risk 0.40cvss 6.1epss 0.01

    Reflected cross site scripting (XSS)

  • CVE-2022-27503MedApr 13, 2022
    risk 0.40cvss 6.1epss 0.00

    Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

  • CVE-2020-8245MedSep 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12,…

  • CVE-2020-8208MedAug 17, 2020
    risk 0.40cvss 6.1epss 0.01

    Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

  • CVE-2020-8198MedJul 10, 2020
    risk 0.40cvss 6.1epss 0.01

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in Stored Cross-Site Scripting (XSS).

  • CVE-2019-11345MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.

  • CVE-2018-10651MedMay 23, 2018
    risk 0.40cvss 6.1epss 0.01

    There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

  • CVE-2018-10649MedMay 23, 2018
    risk 0.40cvss 6.1epss 0.01

    There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

  • CVE-2018-6811MedMar 6, 2018
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.

  • CVE-2016-6259MedAug 2, 2016
    risk 0.40cvss 6.2epss 0.01

    Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

  • CVE-2016-5433MedJun 17, 2016
    risk 0.40cvss 6.1epss 0.00

    Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

  • CVE-2016-4945MedJun 1, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.

  • CVE-2016-2789MedApr 7, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-2072MedFeb 17, 2016
    risk 0.40cvss 6.1epss 0.01

    The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via…

  • CVE-2024-5661MedJun 13, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.

  • CVE-2019-6485MedFeb 22, 2019
    risk 0.39cvss 5.9epss 0.02

    Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before…

  • CVE-2017-5933MedFeb 8, 2017
    risk 0.39cvss 5.9epss 0.03

    Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for remote attackers to obtain the GCM authentication key and spoof data by leveraging…

  • CVE-2016-9385MedJan 23, 2017
    risk 0.39cvss 6.0epss 0.00

    The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.

  • CVE-2020-6175MedMar 16, 2020
    risk 0.38cvss 5.9epss 0.01

    Citrix SD-WAN 10.2.x before 10.2.6 and 11.0.x before 11.0.3 has Missing SSL Certificate Validation.

  • CVE-2019-7218MedMay 13, 2019
    risk 0.38cvss 5.9epss 0.01

    Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase…

  • CVE-2019-11550MedMay 8, 2019
    risk 0.38cvss 5.9epss 0.01

    Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.

  • CVE-2017-17549MedDec 13, 2017
    risk 0.38cvss 5.9epss 0.02

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by…

  • CVE-2015-3642MedAug 2, 2017
    risk 0.38cvss 5.9epss 0.01

    The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8,…

  • CVE-2023-6184MedJan 18, 2024
    risk 0.36cvss 5.0epss 0.47

    Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

  • CVE-2023-24486MedJul 10, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is…

  • CVE-2023-24484MedFeb 16, 2023
    risk 0.36cvss 5.5epss 0.00

    A malicious user can cause log files to be written to a directory that they do not have permission to write to.

  • CVE-2018-19965MedDec 8, 2018
    risk 0.36cvss 5.6epss 0.00

    An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754…

  • CVE-2017-2620MedJul 27, 2018
    risk 0.36cvss 5.5epss 0.04

    Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU…

  • CVE-2017-2615MedJul 3, 2018
    risk 0.36cvss 5.5epss 0.04

    Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process…

  • CVE-2018-3665MedJun 21, 2018
    risk 0.36cvss 5.6epss 0.01

    System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

  • CVE-2017-17565MedDec 12, 2017
    risk 0.36cvss 5.6epss 0.00

    An issue was discovered in Xen through 4.9.x allowing PV guest OS users to cause a denial of service (host OS crash) if shadow mode and log-dirty mode are in place, because of an incorrect assertion related to M2P.

  • CVE-2016-3712MedMay 11, 2016
    risk 0.36cvss 5.5epss 0.01

    Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

  • CVE-2022-27512MedJun 16, 2022
    risk 0.35cvss 5.3epss 0.01

    Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.

  • CVE-2020-13998MedJun 11, 2020
    risk 0.35cvss 5.3epss 0.01

    Citrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because the 2FA error page only occurs after a valid username is entered. NOTE: This vulnerability only affects products that are no longer…

  • CVE-2020-10112MedMar 6, 2020
    risk 0.35cvss 5.4epss 0.01

    Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches static content served under certain URL paths for Citrix Gateway usage. No dynamic content is served under these paths, which implies…

  • CVE-2020-10110MedMar 6, 2020
    risk 0.35cvss 5.3epss 0.03

    Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensitive information disclosure through the cache headers on Citrix ADC. The "Via" header lists cache protocols and recipients between…

  • CVE-2016-6877MedMay 5, 2017
    risk 0.35cvss 5.3epss 0.01

    Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this was not a valid…

  • CVE-2016-9677MedJan 18, 2017
    risk 0.35cvss 5.3epss 0.01

    Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors.

  • CVE-2026-18751MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607.

  • CVE-2022-27516MedNov 8, 2022
    risk 0.34cvss 5.3epss 0.01

    User login brute force protection functionality bypass

  • CVE-2017-5573MedJan 30, 2017
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can cancel tasks of other administrators.

Page 5 of 9