58.483 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
Citrix vulnerabilities
402 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-6830 | MED 4.0 | citrix web_interface The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate a user's web interface session, which allows attackers with access to the same browser instance to gain access to the user's Web Interface | 1.7% | — |
| CVE-2009-3757 | MED 4.3 | citrix xencenterweb Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessi | 1.7% | — |
| CVE-2014-4347 | MED 5.0 | citrix netscaler_access_gateway Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) before 9.3-62.4 and 10.x before 10.1-126.12 allows attackers to obtain sensitive information via vectors related to a cookie. | 1.7% | — |
| CVE-2009-2214 | MED 5.0 | citrix secure_gateway The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request. | 1.7% | — |
| CVE-2020-8253 | HIGH 7.5 | citrix xenmobile_server Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files. | 1.7% | — |
| CVE-2014-4346 | MED 4.3 | citrix netscaler_access_gateway Cross-site scripting (XSS) vulnerability in administration user interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway (formerly Access Gateway Enterprise Edition) 10.1 before 10.1-126.12 allows remote attackers to inject arb | 1.7% | — |
| CVE-2001-0716 | MED 5.0 | citrix metaframe Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server. | 1.7% | — |
| CVE-2007-3679 | MED 4.3 | citrix access_gateway The Citrix EPA ActiveX control (aka the "endpoint checking control" or CCAOControl Object) before 4.5.0.0 in npCtxCAO.dll in Citrix Access Gateway Standard Edition before 4.5.5 and Advanced Edition before 4.5 HF1 allows remote attackers to download and execute | 1.7% | — |
| CVE-2013-6077 | MED 5.8 | citrix xendesktop Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions. | 1.7% | — |
| CVE-2013-6941 | HIGH 10.0 | citrix netscaler_application_delivery_controller_firmware Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors. | 1.7% | — |
| CVE-2020-8257 | CRIT 9.8 | citrix gateway_plug-in Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks | 1.7% | — |
| CVE-2013-2940 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2939 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2938 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2937 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2936 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2935 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2934 | HIGH 10.0 | citrix cloudportal_services_manager Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2013-2933 | HIGH 10.0 | citrix cloudportal_services_manager Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162. | 1.6% | — |
| CVE-2014-8495 | MED 5.0 | citrix xenmobile Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obtain sensitive information by reading the cache. | 1.6% | — |
| CVE-2020-8212 | CRIT 9.8 | citrix xenmobile_server Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality. | 1.6% | — |
| CVE-2013-6943 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames. | 1.6% | — |
| CVE-2017-17549 | MED 5.9 | citrix application_delivery_controller_firmware Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client T | 1.6% | — |
| CVE-2020-8246 | HIGH 7.5 | citrix application_delivery_controller_firmware Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WA | 1.6% | — |
| CVE-2019-12044 | HIGH 7.5 | citrix netscaler_application_delivery_controller_firmware A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x b | 1.5% | — |