Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Workspace HIGH 8.8
CVE-2024-6148

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

Fix: 2404.1+
Fix from $1,950 2024-07-10
Workspace MEDIUM 6.1
CVE-2024-6149

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

Fix: 2404.1+
Fix from $1,600 2024-07-10
Netscaler Console HIGH 8.8
CVE-2024-6235EPSS 21%

Sensitive information disclosure in NetScaler Console

Fix: 14.1-25.53+
Fix from $1,950 2024-07-10
Netscaler Application Delivery Controller HIGH 7.5
CVE-2024-5491

Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

Fix: 12.1-55.304 / 13.0-92.31+
Fix from $1,950 2024-07-10
Netscaler Application Delivery Controller MEDIUM 6.1
CVE-2024-5492

Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

Fix: 12.1-55.304 / 13.0-92.31+
Fix from $1,600 2024-07-10
Xenserver MEDIUM 6.0
CVE-2024-5661

An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause …

Mitigation only
Fix from $1,600 2024-06-13
Sd Wan 1000 Firmware MEDIUM 5.3
CVE-2024-2049

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose …

Fix: 11.4.4.46+
Fix from $1,600 2024-03-12
Virtual Apps And Desktops HIGH 7.2
CVE-2023-6184EPSS 47%

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Fix: after 2311
Fix from $1,950 2024-01-18
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-6549 KEVEPSS 58%

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servi…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Netscaler Application Delivery Controller HIGH 8.8
CVE-2023-6548 KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP…

Fix: 12.1-55.302 / 13.0-92.21+
Fix from $1,950 2024-01-17
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-4967

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual…

Fix: 13.0-92.19 / 13.1-49.15+
Fix from $1,950 2023-10-27
Netscaler Application Delivery Controller HIGH 7.5
CVE-2023-4966 KEVEPSS 100%

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)…

Fix: 12.1-55.300 / 13.0-92.19+
Fix from $1,950 2023-10-10
Netscaler Application Delivery Controller HIGH 8.0
CVE-2023-3467

Privilege Escalation to root administrator (nsroot)

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $1,950 2023-07-19
Netscaler Application Delivery Controller MEDIUM 6.1
CVE-2023-3466

Reflected Cross-Site Scripting (XSS)

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $1,600 2023-07-19
Netscaler Application Delivery Controller CRITICAL 9.8
CVE-2023-3519 KEVEPSS 100%

Unauthenticated remote code execution

Fix: 12.1-55.297 / 13.0-91.13+
Fix from $2,300 2023-07-19
Secure Access Client HIGH 8.8
CVE-2023-24492

A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co…

Fix: 23.5.2+
Fix from $1,950 2023-07-11
Secure Access Client HIGH 7.8
CVE-2023-24491

A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an …

Fix: 23.5.1.3+
Fix from $1,950 2023-07-11
Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2023-24489 KEVEPSS 94%

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at…

Fix: 5.11.24+
Fix from $2,300 2023-07-10
Application Delivery Controller HIGH 7.5
CVE-2023-24487

Arbitrary file read in Citrix ADC and Citrix Gateway 

Fix: 12.1-55.296 / 12.1-65.35+
Fix from $1,950 2023-07-10
Gateway MEDIUM 6.1
CVE-2023-24488EPSS 81%

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

Fix: 12.1-55.296 / 12.1-65.35+
Fix from $1,600 2023-07-10
Workspace MEDIUM 5.5
CVE-2023-24486

A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain acc…

Fix: 2302+
Fix from $1,600 2023-07-10
Workspace HIGH 7.8
CVE-2023-24485

Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…

Fix: 2212+
Fix from $1,950 2023-02-16
Virtual Apps And Desktops HIGH 7.8
CVE-2023-24483

A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citr…

Fix: 2212+
Fix from $1,950 2023-02-16
Workspace MEDIUM 5.5
CVE-2023-24484

A malicious user can cause log files to be written to a directory that they do not have permission to write to.

Fix: 2212+
Fix from $1,600 2023-02-16
Application Delivery Controller HIGH 7.5
CVE-2022-27508

Unauthenticated denial of service

No fix yet
Fix from $1,950 2023-01-26
Gateway MEDIUM 6.5
CVE-2022-27507

Authenticated denial of service

Fix: 12.1-55.278 / 12.1-64.17+
Fix from $1,600 2023-01-26
Application Delivery Controller Firmware MEDIUM 6.5
CVE-2019-18177

In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This aff…

Fix: 13.0-58.30+
Fix from $1,600 2022-12-26
Application Delivery Controller Firmware CRITICAL 9.8
CVE-2022-27518 KEVEPSS 7%

Unauthenticated remote arbitrary code execution

Fix: 12.1-55.291 / 12.1-65.25+
Fix from $2,300 2022-12-13
Gateway CRITICAL 9.8
CVE-2022-27510

Unauthorized access to Gateway user capabilities

Fix: 12.1-55.289 / 12.1-65.21+
Fix from $2,300 2022-11-08
Gateway CRITICAL 9.8
CVE-2022-27516

User login brute force protection functionality bypass

Fix: 12.1-55.289 / 12.1-65.21+
Fix from $2,300 2022-11-08