58.476 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Citrix vulnerabilities
402 CVE
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-5616 | LOW 1.5 | apache cloudstack Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, ( | 0.6% | — |
| CVE-2010-2619 | LOW 1.9 | citrix xenserver Citrix XenServer 5.0 Update 2 and earlier, and 5.5 Update 1 and earlier, when using a pvops kernel, allows guest users to cause a denial of service in the host via unspecified vectors that trigger "incorrectly set flags." | 0.3% | — |
| CVE-2008-6561 | LOW 1.9 | citrix presentation_server_client Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges. | 0.3% | — |
| CVE-2008-5107 | LOW 1.9 | citrix desktop_server The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files. | 0.3% | — |
| CVE-2014-2690 | LOW 2.1 | citrix vdi-in-a-box Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log. | 0.3% | — |
| CVE-2012-3494 | LOW 2.1 | citrix xenserver The set_debugreg hypercall in include/asm-x86/debugreg.h in Xen 4.0, 4.1, and 4.2, and Citrix XenServer 6.0.2 and earlier, when running on x86-64 systems, allows local OS guest users to cause a denial of service (host crash) by writing to the reserved bits of | 0.4% | — |
| CVE-2011-3262 | LOW 2.1 | citrix xen tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the de | 0.3% | — |
| CVE-2007-6267 | LOW 2.1 | citrix edgesight_for_endpoints Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information. | 0.4% | — |
| CVE-2005-4412 | LOW 2.1 | citrix program_neighborhood_client Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly a | 0.4% | — |
| CVE-2005-0822 | LOW 2.1 | citrix metaframe_password_manager Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | 0.4% | — |
| CVE-2004-1902 | LOW 2.1 | citrix metaframe_password_manager The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | 0.4% | — |
| CVE-2022-27506 | LOW 2.7 | citrix sd-wan_1000_firmware Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | 0.7% | — |
| CVE-2010-3699 | LOW 2.7 | citrix xen The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, causes a hang in zenwatch, or prevents unspecified xm commands fro | 0.7% | — |
| CVE-2018-16968 | LOW 3.1 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 allows Directory Traversal. | 1.1% | — |
| CVE-2012-5512 | LOW 3.2 | citrix xenserver Array index error in the HVMOP_set_mem_access handler in Xen 4.1 allows local HVM guest OS administrators to cause a denial of service (crash) or obtain sensitive information via unspecified vectors. | 0.4% | — |
| CVE-2008-6830 | MED 4.0 | citrix web_interface The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface | 1.7% | — |
| CVE-2024-6150 | MED 4.3 | citrix provisioning A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning | 0.2% | — |
| CVE-2020-8275 | MED 4.3 | citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a | 1.9% | — |
| CVE-2020-8196 | MED 4.3 | citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil | 26.3% | |
| CVE-2018-16969 | MED 4.3 | citrix sharefile_storagezones_controller Citrix ShareFile StorageZones Controller before 5.4.2 has Information Exposure Through an Error Message. | 1.1% | — |
| CVE-2016-5109 | MED 4.3 | citrix worx_home Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authenticat | 0.3% | — |
| CVE-2015-7997 | MED 4.3 | citrix netscaler_application_delivery_controller_firmware Multiple cross-site scripting (XSS) vulnerabilities in the Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delive | 1.0% | — |
| CVE-2015-6672 | MED 4.3 | citrix netscaler_application_delivery_controller_firmware Cross-site scripting (XSS) vulnerability in the Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allows remote attacke | 1.4% | — |
| CVE-2015-2840 | MED 4.3 | citrix netscaler Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter. | 1.9% | — |
| CVE-2015-2839 | MED 4.3 | citrix netscaler The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro | 2.0% | — |