Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2026-3055 KEVEPSS 84%

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

Fix: 13.1-37.262 / 13.1-62.23+
Fix from $2,300 2026-03-23
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2025-7775 KEVEPSS 20%

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is conf…

Fix: 12.1-55.330 / 13.1-37.241+
Fix from $2,300 2025-08-26
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2025-6543 KEVEPSS 10%

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gate…

Fix: 13.1-37.236 / 13.1-59.19+
Fix from $2,300 2025-06-25
Netscaler Application Delivery Controller HIGH 7.5
CVE-2025-5777 KEVEPSS 100%

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Prox…

Fix: 12.1-55.328 / 13.1-37.235+
Fix from $1,950 2025-06-17
Session Recording HIGH 8.0
CVE-2024-8068 KEV

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Activ…

Fix: 2407+
Fix from $1,950 2024-11-12
Session Recording HIGH 8.0
CVE-2024-8069 KEVEPSS 15%

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user …

Fix: 2407+
Fix from $1,950 2024-11-12
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-6549 KEVEPSS 58%

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servi…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Netscaler Application Delivery Controller HIGH 8.8
CVE-2023-6548 KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-4966 KEVEPSS 100%

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)…

Fix: 12.1-55.300 / 13.0-92.19+
Fix from $1,950 2023-10-10
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2023-3519 KEVEPSS 100%

Unauthenticated remote code execution

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $2,300 2023-07-19
Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2023-24489 KEVEPSS 94%

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at…

Fix: 5.11.24+
Fix from $2,300 2023-07-10
Application Delivery Controller Firmware CRITICAL 9.8
CVE-2022-27518 KEVEPSS 7%

Unauthenticated remote arbitrary code execution

Fix: 12.1-55.291 / 12.1-65.25+
Fix from $2,300 2022-12-13
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22941 KEVEPSS 54%

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the …

Fix: 5.11.20+
Fix from $2,300 2021-09-23
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8193 KEVEPSS 88%

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDW…

Fix: 10.2.7 / 10.5-70.18+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2020-8195 KEVEPSS 33%

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix S…

Fix: 1.0.0.137 / 10.2.7+
Fix from $1,600 2020-07-10
Application Delivery Controller Firmware CRITICAL 9.8
CVE-2019-19781 KEVEPSS 100%

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

Mitigation only
Fix from $2,300 2019-12-27
Storefront Server HIGH 7.5
CVE-2019-13608 KEVEPSS 30%

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

Fix: 3.0.8000 / 3.12.4000+
Fix from $1,950 2019-08-29
Netscaler Sd Wan HIGH 8.8
CVE-2019-12991 KEVEPSS 74%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

Fix: 10.0.8 / 10.2.3+
Fix from $1,950 2019-07-16
Netscaler Sd Wan CRITICAL 9.8
CVE-2019-12989 KEVEPSS 94%

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

Fix: 10.0.8 / 10.2.3+
Fix from $2,300 2019-07-16
Receiver CRITICAL 9.8
CVE-2019-11634 KEVEPSS 8%

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Fix: 1904+
Fix from $2,300 2019-05-22
Netscaler Sd Wan CRITICAL 9.8
CVE-2017-6316 KEVEPSS 73%

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. O…

Fix: after 9.1.2.26.561201
Fix from $2,300 2017-07-20