58.483 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Citrix vulnerabilities
402 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-8274 | MED 6.5 | citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android | 2.0% | — |
| CVE-2009-2213 | MED 6.5 | citrix netscaler_access_gateway The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticate | 2.0% | — |
| CVE-2020-10111 | HIGH 7.5 | citrix gateway_firmware Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a security issue. Citrix ADC only caches HTTP/1.1 traffic for performance optimization | 2.0% | — |
| CVE-2019-7217 | HIGH 7.5 | citrix sharefile Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required. | 2.0% | — |
| CVE-2015-2839 | MED 4.3 | citrix netscaler The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the file_name JSON member in params/xen_hotfix/0 to nitro | 2.0% | — |
| CVE-2015-2829 | HIGH 7.8 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.5 Build 53.9 through 55.8 and 10.5.e Build 53-9010.e allow remote attackers to cause a denial of service (reboot) via unspecified vectors. | 2.0% | — |
| CVE-2008-3253 | MED 4.3 | citrix xenserver Cross-site scripting (XSS) vulnerability in the XenAPI HTTP interfaces in Citrix XenServer Express, Standard, and Enterprise Edition 4.1.0; Citrix XenServer Dell Edition (Express and Enterprise) 4.1.0; and HP integrated Citrix XenServer (Select and Enterprise) | 2.0% | — |
| CVE-2018-17446 | CRIT 9.8 | citrix netscaler_sd-wan A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | 2.0% | — |
| CVE-2020-8187 | HIGH 7.5 | citrix application_delivery_controller_firmware Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack. | 1.9% | — |
| CVE-2018-17447 | HIGH 7.5 | citrix netscaler_sd-wan An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. | 1.9% | — |
| CVE-2015-2840 | MED 4.3 | citrix netscaler Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery parameter. | 1.9% | — |
| CVE-2014-3798 | MED 6.5 | citrix xenserver The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame. | 1.9% | — |
| CVE-2016-9680 | HIGH 7.5 | citrix provisioning_services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors. | 1.9% | — |
| CVE-2014-4948 | MED 6.4 | citrix xenserver Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD). | 1.9% | — |
| CVE-2020-8275 | MED 4.3 | citrix secure_mail Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a | 1.9% | — |
| CVE-2014-2881 | HIGH 10.0 | citrix netscaler_access_gateway Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and ve | 1.9% | — |
| CVE-2016-4945 | MED 6.1 | citrix netscaler_gateway_11.0_firmware Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie. | 1.9% | — |
| CVE-2016-9028 | HIGH 8.8 | citrix netscaler_application_delivery_controller_firmware Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header. | 1.8% | — |
| CVE-2020-8197 | HIGH 8.8 | citrix application_delivery_controller_firmware Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands. | 1.8% | — |
| CVE-2017-9231 | HIGH 7.5 | citrix xenmobile_server XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors. | 1.8% | — |
| CVE-2016-9111 | MED 6.8 | citrix receiver_desktop Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not rep | 1.8% | — |
| CVE-2012-6314 | MED 5.0 | citrix xendesktop Citrix XenDesktop Virtual Desktop Agent (VDA) 5.6.x before 5.6.200, when making changes to the server-side policy that control USB redirection, does not propagate changes to the VDA, which allows authenticated users to retain access to the USB device. | 1.8% | — |
| CVE-2007-3625 | MED 5.0 | citrix metaframe_presentation_server The Program Neighborhood Agent in Citrix Presentation Server Clients for 32-bit Windows before 10.100 allows remote attackers to cause a denial of service (agent exit) via a certain request that uses content redirection and a long pathname. | 1.8% | — |
| CVE-2010-4515 | MED 4.3 | citrix web_interface Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-6477 and CVE-2009-2454. | 1.8% | — |
| CVE-2016-6273 | HIGH 7.5 | citrix license_server The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause | 1.8% | — |