58.465 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Citrix vulnerabilities
402 CVE
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-88773 | CRIT 10.0 | citrix netscaler_application_delivery_controller Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 a | 0.4% | — |
| CVE-2019-9548 | CRIT 10.0 | citrix application_delivery_management Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control. | 1.5% | — |
| CVE-2015-5538 | HIGH 10.0 | citrix netscaler_application_delivery_controller_firmware Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors | 3.2% | — |
| CVE-2014-4947 | HIGH 10.0 | citrix xenserver Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors. | 5.4% | — |
| CVE-2014-2882 | HIGH 10.0 | citrix netscaler_access_gateway Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation. | 1.1% | — |
| CVE-2014-2881 | HIGH 10.0 | citrix netscaler_access_gateway Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and ve | 1.9% | — |
| CVE-2013-6941 | HIGH 10.0 | citrix netscaler_application_delivery_controller_firmware Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors. | 1.7% | — |
| CVE-2013-2940 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2939 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2938 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2937 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2936 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2935 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2934 | HIGH 10.0 | citrix cloudportal_services_manager Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2933 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2012-4501 | HIGH 10.0 | apache cloudstack Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs. | 7.8% | — |
| CVE-2009-2452 | HIGH 10.0 | citrix licensing Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console." | 2.1% | — |
| CVE-2008-2528 | HIGH 10.0 | citrix access_gateway Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors. | 2.7% | — |
| CVE-2008-0356 | HIGH 10.0 | citrix access_essentials Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code | 73.0% | — |
| CVE-2007-2850 | HIGH 10.0 | citrix access_essentials The Session Reliability Service (XTE) in Citrix MetaFrame Presentation Server 3.0, Presentation Server 4.0, and Access Essentials 1.0 and 1.5, allows remote attackers to bypass network security policies and connect to arbitrary TCP ports via a modified address | 2.8% | — |
| CVE-2000-0244 | HIGH 10.0 | citrix metaframe The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. | 2.3% | — |
| CVE-2026-88777 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and befor | 0.4% | — |
| CVE-2026-88776 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before | 0.4% | — |
| CVE-2026-88775 | CRIT 9.8 | citrix netscaler_application_delivery_controller Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 l | 0.4% | — |
| CVE-2026-88771 | CRIT 9.8 | citrix netscaler_application_delivery_controller Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13 | 1.1% |