Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2024-6148
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
Workspace
2404.1+
MEDIUM 6.1
CVE-2024-6149
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
Workspace
2404.1+
HIGH 8.8
CVE-2024-6235EPSS 21%
Sensitive information disclosure in NetScaler Console
Netscaler Console
14.1-25.53+
HIGH 7.5
CVE-2024-5491
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
Netscaler Application Delivery Controller
12.1-55.304 / 13.0-92.31+
MEDIUM 6.1
CVE-2024-5492
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
Netscaler Application Delivery Controller
12.1-55.304 / 13.0-92.31+
MEDIUM 6.0
CVE-2024-5661
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause …
Xenserver
Mitigation only
MEDIUM 5.3
CVE-2024-2049
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose …
Sd Wan 1000 Firmware
11.4.4.46+
HIGH 7.2
CVE-2023-6184EPSS 47%
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Virtual Apps And Desktops
after 2311
HIGH 7.5
CVE-2023-6549 KEVEPSS 58%
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Servi…
Netscaler Application Delivery Controller
12.1-55.302 / 13.0-92.21+
HIGH 8.8
CVE-2023-6548 KEV
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP…
Netscaler Application Delivery Controller
12.1-55.302 / 13.0-92.21+
HIGH 7.5
CVE-2023-4967
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual…
Netscaler Application Delivery Controller
13.0-92.19 / 13.1-49.15+
HIGH 7.5
CVE-2023-4966 KEVEPSS 100%
Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy)…
Netscaler Application Delivery Controller
12.1-55.300 / 13.0-92.19+
HIGH 8.0
CVE-2023-3467
Privilege Escalation to root administrator (nsroot)
Netscaler Application Delivery Controller
12.1-55.297 / 13.0-91.13+
MEDIUM 6.1
CVE-2023-3466
Reflected Cross-Site Scripting (XSS)
Netscaler Application Delivery Controller
12.1-55.297 / 13.0-91.13+
CRITICAL 9.8
CVE-2023-3519 KEVEPSS 100%
Unauthenticated remote code execution
Netscaler Application Delivery Controller
12.1-55.297 / 13.0-91.13+
HIGH 8.8
CVE-2023-24492
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute co…
Secure Access Client
23.5.2+
HIGH 7.8
CVE-2023-24491
A vulnerability has been discovered in the Citrix Secure Access client for Windows
which, if exploited, could allow an attacker with access to an …
Secure Access Client
23.5.1.3+
CRITICAL 9.8
CVE-2023-24489 KEVEPSS 94%
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated at…
Sharefile Storage Zones Controller
5.11.24+
HIGH 7.5
CVE-2023-24487
Arbitrary file read in Citrix ADC and Citrix Gateway
Application Delivery Controller
12.1-55.296 / 12.1-65.35+
MEDIUM 6.1
CVE-2023-24488EPSS 81%
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting
Gateway
12.1-55.296 / 12.1-65.35+
MEDIUM 5.5
CVE-2023-24486
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain acc…
Workspace
2302+
HIGH 7.8
CVE-2023-24485
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix…
Workspace
2212+
HIGH 7.8
CVE-2023-24483
A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citr…
Virtual Apps And Desktops
2212+
MEDIUM 5.5
CVE-2023-24484
A malicious user can cause log files to be written to a directory that they do not have permission to write to.
Workspace
2212+
HIGH 7.5
CVE-2022-27508
Unauthenticated denial of service
Application Delivery Controller
No fix yet
MEDIUM 6.5
CVE-2022-27507
Authenticated denial of service
Gateway
12.1-55.278 / 12.1-64.17+
MEDIUM 6.5
CVE-2019-18177
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This aff…
Application Delivery Controller Firmware
13.0-58.30+
CRITICAL 9.8
CVE-2022-27518 KEVEPSS 7%
Unauthenticated remote arbitrary code execution
Application Delivery Controller Firmware
12.1-55.291 / 12.1-65.25+
CRITICAL 9.8
CVE-2022-27510
Unauthorized access to Gateway user capabilities
Gateway
12.1-55.289 / 12.1-65.21+
CRITICAL 9.8
CVE-2022-27516
User login brute force protection functionality bypass
Gateway
12.1-55.289 / 12.1-65.21+