Vulnerability index

Browse CVEs

331 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gateway CRITICAL 9.6
CVE-2022-27513

Remote desktop takeover via phishing

Fix: 12.1-55.289 / 12.1-65.21+
Fix from $2,300 2022-11-08
Gateway MEDIUM 6.1
CVE-2022-27509

Unauthenticated redirection to a malicious website

Fix: 12.1-55.282 / 12.1-65.15+
Fix from $1,600 2022-07-28
Application Delivery Management HIGH 8.1
CVE-2022-27511EPSS 12%

Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device…

Fix: 13.0-85.19 / 13.1-21.53+
Fix from $1,950 2022-06-16
Application Delivery Management MEDIUM 5.3
CVE-2022-27512

Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.

Fix: 13.0-85.19 / 13.1-21.53+
Fix from $1,600 2022-06-16
Gateway Plug In HIGH 7.1
CVE-2022-21827

An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could…

Fix: 21.9.1.2+
Fix from $1,950 2022-05-26
Xenmobile Server HIGH 8.8
CVE-2021-44519

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

Mitigation only
Fix from $1,950 2022-04-19
Storefront Server MEDIUM 6.1
CVE-2022-27503

Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9

Fix: 3.12.9000 / 1912.0.5000+
Fix from $1,600 2022-04-13
Sd Wan 110 Firmware MEDIUM 6.1
CVE-2022-27505

Reflected cross site scripting (XSS)

Fix: 11.4.3a+
Fix from $1,600 2022-04-13
Xenmobile Server HIGH 8.8
CVE-2021-44520EPSS 6%

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root p…

Mitigation only
Fix from $1,950 2022-04-13
Xenmobile Server HIGH 7.2
CVE-2022-26151EPSS 8%

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

Mitigation only
Fix from $1,950 2022-04-13
Workspace HIGH 7.8
CVE-2022-21825

An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacke…

Fix: 2112+
Fix from $1,950 2022-02-09
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22955

A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or …

Fix: 11.1-65.23 / 12.1-63.22+
Fix from $1,950 2021-12-07
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22956

An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with acc…

Fix: 10.2.9c / 11.1-65.23+
Fix from $1,950 2021-12-07
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22941 KEVEPSS 54%

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the …

Fix: 5.11.20+
Fix from $2,300 2021-09-23
Sharefile Storagezones Controller HIGH 7.5
CVE-2021-22932

An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryptio…

Fix: 5.11.19+
Fix from $1,950 2021-08-16
Application Delivery Controller Firmware HIGH 8.1
CVE-2021-22927

A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provider that could allow an attacke…

Fix: 11.1-65.22 / 12.1-55.238+
Fix from $1,950 2021-08-05
Virtual Apps And Desktops HIGH 7.8
CVE-2021-22928

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citri…

Fix: after 2106
Fix from $1,950 2021-08-05
Application Delivery Management MEDIUM 6.5
CVE-2021-22920

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Cit…

Mitigation only
Fix from $1,600 2021-08-05
Application Delivery Controller Firmware HIGH 7.5
CVE-2021-22919

A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Cit…

Fix: 10.2.9.b / 11.1-65.22+
Fix from $1,950 2021-08-05
Cloud Connector HIGH 7.5
CVE-2021-22914

Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Ci…

Fix: 6.31.0.62192+
Fix from $1,950 2021-06-16
Gateway MEDIUM 6.5
CVE-2020-8299

Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WA…

Fix: 10.2.9a / 11.1.2c+
Fix from $1,600 2021-06-16
Gateway MEDIUM 6.5
CVE-2020-8300

Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper ac…

Fix: 11.1-65.20 / 12.1-55.238+
Fix from $1,600 2021-06-16
Workspace HIGH 7.8
CVE-2021-22907

An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalation in CR versions prior to 2…

Fix: 19.12.4000 / 2105+
Fix from $1,950 2021-05-27
Sharefile Storagezones Controller CRITICAL 9.8
CVE-2021-22891

A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow un…

Fix: 5.7.3 / 5.9.3+
Fix from $2,300 2021-05-27
Secure Mail MEDIUM 6.5
CVE-2020-8274

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated acce…

Fix: 20.11.0+
Fix from $1,600 2021-01-06
Gateway Plug In CRITICAL 9.8
CVE-2020-8257

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to…

Fix: after 13.0-61.48
Fix from $2,300 2020-12-14
Virtual Apps And Desktops HIGH 8.8
CVE-2020-8283

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before …

Fix: 7.6 / 7.15+
Fix from $1,950 2020-12-14
Gateway Plug In HIGH 7.5
CVE-2020-8258

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, allows …

Fix: after 13.0-61.48
Fix from $1,950 2020-12-14
Sd Wan CRITICAL 9.8
CVE-2020-8271EPSS 11%

Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

Fix: 10.2.8 / 11.1.2b+
Fix from $2,300 2020-11-16
Virtual Apps And Desktops HIGH 8.8
CVE-2020-8269

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285…

Fix: 7.6 / 7.15+
Fix from $1,950 2020-11-16