← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal.
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
Jul 16, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).
1Citrix
1Xenserver
Nov 21, 2024
Jul 11, 2019
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
1Citrix
1Appdna
Jun 17, 2026
Jun 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
1Citrix
1Application Delivery Management
Jun 17, 2026
Jun 5, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
1Citrix
1Xenmobile Server
Nov 21, 2024
Jun 5, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobi...Show more
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions on behalf of any Mobile Application Management (MAM) enrolled device.Show less
1Citrix
2Citrix Sd Wan Center
Netscaler Sd Wan Center
Jun 17, 2026
Jun 3, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection.
1Citrix
2Receiver
Workspace
Jun 17, 2026
May 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
1Citrix
2Netscaler Application Delivery Controller Firmware
Netscaler Gateway Firmware
Jun 17, 2026
May 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5....Show more
A Buffer Overflow exists in Citrix NetScaler Gateway 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23 and Citrix Application Delivery Controller 10.5.x before 10.5.70.x, 11.1.x before 11.1.59.10, 12.0.x before 12.0.59.8, and 12.1.x before 12.1.49.23.Show less
1Citrix
1Sharefile
Jun 17, 2026
May 13, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator)...Show more
Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacker with access to the offline victim's otp physical token or virtual app (like google authenticator) is able to bypass the first authentication phase (username/password mechanism) and log-in using username/otp combination only (phase 2 of 2FA).Show less
1Citrix
1Sharefile
Jun 17, 2026
May 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on different server responses using the request to check the otp code. No authentication is required.
1Citrix
2Netscaler Sd Wan
Sd Wan
Jun 17, 2026
May 8, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
1Citrix
2Netscaler Application Delivery Controller Firmware
Netscaler Gateway Firmware
Jun 17, 2026
Feb 22, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12...Show more
Citrix NetScaler Gateway 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 and Application Delivery Controller (ADC) 12.1 before build 50.31, 12.0 before build 60.9, 11.1 before build 60.14, 11.0 before build 72.17, and 10.5 before build 69.5 allow remote attackers to obtain sensitive plaintext information because of a TLS Padding Oracle Vulnerability when CBC-based cipher suites are enabled.Show less
3Citrix
DebianXen
3Debian Linux
XenXenserver
Nov 21, 2024
Dec 8, 2018
N/A· v4
5.6 MEDIUM· v3
4.7 MEDIUM· v2
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE...Show more
An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.Show less
3Citrix
DebianXen
3Debian Linux
XenXenserver
Nov 21, 2024
Dec 8, 2018
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.