Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2019-11345
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
Citrix Sd Wan Center
10.0.7 / 10.2.1+
HIGH 7.5
CVE-2020-10111
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests. NOTE: Citrix disputes the reported behavior as not a securit…
Gateway Firmware
No fix yet
MEDIUM 5.4
CVE-2020-10112
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning. NOTE: Citrix disputes this as not a vulnerability. By default, Citrix ADC only caches sta…
Gateway Firmware
No fix yet
MEDIUM 5.3
CVE-2020-10110
Citrix Gateway 11.1, 12.0, and 12.1 allows Information Exposure Through Caching. NOTE: Citrix disputes this as not a vulnerability. There is no sensi…
Gateway Firmware
No fix yet
HIGH 7.8
CVE-2012-4606
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vu…
Xenserver
Mitigation only
HIGH 7.8
CVE-2012-4603EPSS 7%
Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute ar…
Receiver
after 12.1
HIGH 8.1
CVE-2013-3619EPSS 10%
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicr…
Netscaler Sdx Firmware
3.12 / 3.15+
HIGH 7.5
CVE-2013-3620
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (…
Netscaler Sdx Firmware
3.12 / 3.15+
CRITICAL 9.8
CVE-2019-19781 KEVEPSS 100%
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
Application Delivery Controller Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-18225
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before …
Application Delivery Controller Firmware
Mitigation only
HIGH 8.8
CVE-2019-17366
Citrix Application Delivery Management (ADM) 12.1 before build 54.13 has Incorrect Access Control.
Application Delivery Management
No fix yet
HIGH 7.5
CVE-2019-13608 KEVEPSS 30%
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Storefront Server
3.0.8000 / 3.12.4000+
CRITICAL 9.8
CVE-2019-12990EPSS 39%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
Netscaler Sd Wan
10.0.8 / 10.2.3+
HIGH 8.8
CVE-2019-12991 KEVEPSS 74%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
HIGH 8.8
CVE-2019-12992EPSS 49%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12985EPSS 40%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12986EPSS 40%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12987EPSS 43%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12988EPSS 43%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
Netscaler Sd Wan
10.0.8 / 10.2.3+
CRITICAL 9.8
CVE-2019-12989 KEVEPSS 94%
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
Netscaler Sd Wan
10.0.8 / 10.2.3+
MEDIUM 6.5
CVE-2014-3798
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted E…
Xenserver
Patch available
CRITICAL 9.8
CVE-2019-12292
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
Appdna
after 7.18
CRITICAL 10.0
CVE-2019-9548
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
Application Delivery Management
after 13.0.33.23
CRITICAL 9.1
CVE-2018-18571
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patc…
Xenmobile Server
Mitigation only
CRITICAL 9.8
CVE-2019-10883EPSS 65%
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
Citrix Sd Wan Center
10.0.7 / 10.2.1+
CRITICAL 9.8
CVE-2019-11634 KEVEPSS 8%
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
Receiver
1904+
HIGH 7.5
CVE-2019-12044
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12…
Netscaler Gateway Firmware
10.5.70 / 11.1.59.10+
HIGH 7.5
CVE-2019-7217
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the…
Sharefile
19.12+
MEDIUM 5.9
CVE-2019-7218
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline …
Sharefile
after 19.1
MEDIUM 5.9
CVE-2019-11550
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
Netscaler Sd Wan
10.0.7 / 10.2.1+