IT
58.476 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

Citrix vulnerabilities

402 CVE

Citrix vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2011-2592 HIGH 9.3 citrix access_gateway_plug-in Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a 14.9% —
CVE-2020-7473 HIGH 7.5 citrix sharefile_storagezones_controller In certain situations, all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020, allow unauthenticated attackers to access the documents and folders of ShareFile users. NOTE: unlike 14.3% —
CVE-2007-0444 HIGH 7.2 citrix metaframe Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) En 14.0% —
CVE-2017-17382 MED 5.9 citrix application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote attackers to decrypt TLS ciphertext data by leveraging a Blei 13.9% —
CVE-2024-12284 HIGH 8.8 citrix netscaler_agent Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. 13.3% —
CVE-2022-27511 HIGH 8.1 citrix application_delivery_management Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the d 12.4% —
CVE-2015-7705 CRIT 9.8 citrix xenserver The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. 12.4% —
CVE-2020-8271 CRIT 9.8 citrix sd-wan Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8 11.1% —
CVE-2018-17445 CRIT 9.8 citrix netscaler_sd-wan A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. 11.1% —
CVE-2015-7704 HIGH 7.5 citrix xenserver The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. 10.9% —
CVE-2025-4365 HIGH 7.5 citrix netscaler_console Arbitrary file read in NetScaler Console and NetScaler SDX (SVM) 10.8% —
CVE-2015-2682 MED 5.0 citrix command_center Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via a direct request to conf/securitydbData.xml. 10.7% —
CVE-2020-8194 MED 6.5 citrix application_delivery_controller_firmware Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file download. 10.7% —
CVE-2013-3619 HIGH 8.1 citrix netscaler_firmware Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd we 9.7% —
CVE-2002-0504 HIGH 7.5 citrix nfuse Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. 7.9% —
CVE-2012-4501 HIGH 10.0 apache cloudstack Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user account, as demonstrated by API calls to delete VMs. 7.8% —
CVE-2022-26151 HIGH 7.2 citrix xenmobile_server Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. 7.3% —
CVE-2012-4603 HIGH 7.8 citrix receiver Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver. 6.9% —
CVE-2025-7776 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to i 6.9% —
CVE-2010-2991 HIGH 9.3 citrix online_plug-in_for_windows_for_xenapp_\&_xendesktop The IICAClient interface in the ICAClient library in the ICA Client ActiveX Object (aka ICO) component in Citrix Online Plug-in for Windows for XenApp & XenDesktop before 12.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (me 6.8% —
CVE-2018-10653 CRIT 9.8 citrix xenmobile_server There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. 6.8% —
CVE-2013-2758 MED 5.0 apache cloudstack Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable sequence, which makes it easier for remote attackers to guess the console access URL via a brute force attack. 6.5% —
CVE-2025-5349 HIGH 8.8 citrix netscaler_application_delivery_controller Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway 6.2% —
CVE-2018-7218 CRIT 9.8 citrix application_delivery_controller_firmware The AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.24, 11.1 before Build 58.13, and 12.0 before Build 57.24 allows remote attackers to execute arbitrary code via 6.2% —
CVE-2013-2756 MED 5.0 apache cloudstack Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code. 5.8% —