← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
2Netscaler Application Delivery Controller
Netscaler Gateway
Jun 17, 2026
Nov 12, 2024
8.4 HIGH· v4
8.1 HIGH· v3
N/A· v2
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be...Show more
Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway (VPN Vserver) OR the appliance must be configured as a Auth Server (AAA Vserver) with RDP Feature enabledShow less
1Citrix
1Session Recording
Jun 17, 2026
Nov 12, 2024
5.1 MEDIUM· v4
8.0 HIGH· v3
N/A· v2
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
1Citrix
1Session Recording
Jun 17, 2026
Nov 12, 2024
5.1 MEDIUM· v4
8.0 HIGH· v3
N/A· v2
Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain
1Citrix
1Workspace
Jun 17, 2026
Sep 11, 2024
5.4 MEDIUM· v4
7.3 HIGH· v3
N/A· v2
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
1Citrix
1Workspace
Jun 17, 2026
Sep 11, 2024
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
1Citrix
1Workspace
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exp...Show more
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.Show less
1Citrix
1Uberagent
Jun 17, 2026
Jul 12, 2024
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
Privilege escalation in uberAgent
1Citrix
1Workspace
Jun 17, 2026
Jul 10, 2024
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
1Citrix
3Netscaler Agent
Netscaler ConsoleNetscaler Sdx
Jun 17, 2026
Jul 10, 2024
7.1 HIGH· v4
7.5 HIGH· v3
N/A· v2
Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX
1Citrix
1Virtual Apps And Desktops
Jun 17, 2026
Jul 10, 2024
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS
1Citrix
1Provisioning
Jun 17, 2026
Jul 10, 2024
4.8 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
1Citrix
1Workspace
Jun 17, 2026
Jul 10, 2024
4.8 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
1Citrix
1Workspace
Jun 17, 2026
Jul 10, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
N/A· v2
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
1Citrix
1Netscaler Console
Jun 17, 2026
Jul 10, 2024
9.4 CRITICAL· v4
8.8 HIGH· v3
N/A· v2
Sensitive information disclosure in NetScaler Console
1Citrix
2Netscaler Application Delivery Controller
Netscaler Gateway
Jun 17, 2026
Jul 10, 2024
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
1Citrix
2Netscaler Application Delivery Controller
Netscaler Gateway
Jun 17, 2026
Jul 10, 2024
7.2 HIGH· v4
7.5 HIGH· v3
N/A· v2
Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler
1Citrix
2Hypervisor
Xenserver
Jun 17, 2026
Jun 13, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
7Cisco
CitrixF5+4 more
9Anyconnect Vpn Client
Big Ip Access Policy ManagerClient Connector+6 more
Jun 17, 2026
May 6, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface....Show more
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.Show less
1Citrix
12Sd Wan 1000 Firmware
Sd Wan 1100 FirmwareSd Wan 110 Firmware+9 more
Jun 17, 2026
Mar 12, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.
1Citrix
1Virtual Apps And Desktops
Jun 17, 2026
Jan 18, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting