imPC@ndo EN

Vulnerabilità Citrix

393 CVE

CVE-2023-4966
Ransomware Critica 9.4

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2014-6271
Sfruttata Critica 9.8

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2019-19781
Ransomware Critica 9.8

An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware
1.00EPSS
CVE-2025-5777
Ransomware Alta 7.5

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2014-7169
Sfruttata Critica 9.8

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as …

apple mac_os_x · arista eos · canonical ubuntu_linux · checkpoint security_gateway · e altri 70
1.00EPSS
CVE-2023-3519
Ransomware Critica 9.8

Unauthenticated remote code execution

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
1.00EPSS
CVE-2023-24489
Sfruttata Critica 9.8

A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

citrix sharefile_storage_zones_controller
0.95EPSS
CVE-2019-12989
Sfruttata Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

citrix netscaler_sd-wan · citrix sd-wan
0.94EPSS
CVE-2020-8193
Sfruttata Media 6.5

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows unauthenticated access to certain URL endpoints.

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.88EPSS
CVE-2026-3055
Sfruttata Critica 9.8

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.84EPSS
CVE-2019-12991
Sfruttata Alta 8.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.74EPSS
CVE-2017-6316
Sfruttata Critica 9.8

Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.…

citrix netscaler_sd-wan
0.73EPSS
CVE-2023-6549
Sfruttata Alta 8.2

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.58EPSS
CVE-2021-22941
Ransomware Critica 9.8

Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

citrix sharefile_storagezones_controller
0.54EPSS
CVE-2020-8195
Sfruttata Media 6.5

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low priv…

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix gateway_plug-in_for_linux · citrix netscaler_gateway_firmware · e altri 1
0.33EPSS
CVE-2019-13608
Ransomware Alta 7.5

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

citrix storefront_server
0.30EPSS
CVE-2020-8196
Sfruttata Media 4.3

Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil…

citrix application_delivery_controller_firmware · citrix gateway_firmware · citrix netscaler_gateway_firmware · citrix sd-wan_wanop
0.26EPSS
CVE-2025-7775
Sfruttata Critica 9.8

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC a…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.20EPSS
CVE-2024-8069
Sfruttata Alta 8.0

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

citrix session_recording
0.15EPSS
CVE-2025-6543
Sfruttata Critica 9.8

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.10EPSS
CVE-2019-11634
Ransomware Critica 9.8

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

citrix receiver · citrix workspace
0.08EPSS
CVE-2022-27518
Sfruttata Critica 9.8

Unauthenticated remote arbitrary code execution

citrix application_delivery_controller_firmware · citrix gateway_firmware
0.07EPSS
CVE-2023-6548
Sfruttata Media 5.5

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interf…

citrix netscaler_application_delivery_controller · citrix netscaler_gateway
0.03EPSS
CVE-2024-8068
Sfruttata Alta 8.0

Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

citrix session_recording
0.01EPSS
CVE-2023-24488
Media 6.1

Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting

citrix application_delivery_controller · citrix gateway
0.81EPSS