← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors.
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecifie...Show more
Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.Show less
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vecto...Show more
Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to "RADIUS authentication."Show less
1Citrix
1Netscaler Application Delivery Controller Firmware
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10...Show more
Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to the "Virtual Machine Daemon."Show less
1Citrix
2Sharefile Mobile
Sharefile Mobile For Tablets
Apr 29, 2026
Feb 21, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive informati...Show more
Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.Show less
1Citrix
2Xenmobile Device Manager
Xenmobile Device Manager Mdm
Apr 29, 2026
Feb 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors.
1Citrix
1Gotomeeting
Apr 29, 2026
Jan 26, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application th...Show more
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.Show less
1Citrix
1Xendesktop
Apr 29, 2026
Nov 5, 2013
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.
1Citrix
2Netscaler Application Delivery Controller
Netscaler Application Delivery Controller Firmware
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
Citrix NetScaler Application Delivery Controller (ADC) 10.0 before 10.0-76.7 allows remote attackers to cause a denial of service (nsconfigd crash and appliance reboot) via a crafted request.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVE...Show more
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.Show less
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CV...Show more
Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.Show less
1Citrix
1Cloudportal Services Manager
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.
1Citrix
1Xenclient Xt
Apr 29, 2026
Sep 12, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection.
1Citrix
2Netscaler Access Gateway
Netscaler Access Gateway Firmware
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypa...Show more
Unspecified vulnerability in Citrix NetScaler Access Gateway Enterprise Edition (AGEE) before 9.3.62.4 and 10.x through 10.0.74.4, and NetScaler AGEE Common Criteria build before 9.3.53.6, allows remote attackers to bypass intended intranet access restrictions via unknown vectors.Show less
1Citrix
1Access Gateway
Apr 29, 2026
Mar 19, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors.