← Back

Citrix

citrix

393 CVEs • 153 products

Products (153)

Click to collapse
Toggle
Xenserver
xenserver
Gateway
gateway
Sd Wan
sd-wan
Workspace
workspace
Metaframe
metaframe
Netscaler
netscaler
Sd Wan Wanop
sd-wan_wanop
Xen
xen
Xenapp
xenapp
Xendesktop
xendesktop
Nfuse
nfuse
Web Interface
web_interface
Xencenterweb
xencenterweb
Cloudplatform
cloudplatform
Vdi In A Box
vdi-in-a-box
Netscaler Sdx
netscaler_sdx
Sharefile
sharefile
Receiver
receiver
Workspace App
workspace_app
Secure Mail
secure_mail
Winframe
winframe
Ica Client
ica_client
Xp
xp
Secure Gateway
secure_gateway
Licensing
licensing
Cloudstack
cloudstack
Xenclient Xt
xenclient_xt
Gotomeeting
gotomeeting

CVEs (393)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
2Application Delivery Controller Firmware
Gateway Firmware
Jun 17, 2026
Dec 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated remote arbitrary code execution
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
User login brute force protection functionality bypass
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Remote desktop takeover via phishing
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Nov 8, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthorized access to Gateway user capabilities
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Jul 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauthenticated redirection to a malicious website
1Citrix
1Application Delivery Management
Jun 17, 2026
Jun 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM.
1Citrix
1Application Delivery Management
Jun 17, 2026
Jun 16, 2022
N/A· v4
8.1 HIGH· v3
7.8 HIGH· v2
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the defau...Show more
Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.Show less
1Citrix
1Gateway Plug In
Jun 17, 2026
May 26, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citri...Show more
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.Show less
1Citrix
1Xenmobile Server
Jun 17, 2026
Apr 19, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
1Citrix
14Sd Wan 1000 Firmware
Sd Wan 1100 FirmwareSd Wan 110 Firmware+11 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
2.7 LOW· v3
6.8 MEDIUM· v2
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
1Citrix
12Sd Wan 1000 Firmware
Sd Wan 1100 FirmwareSd Wan 110 Firmware+9 more
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected cross site scripting (XSS)
1Citrix
1Storefront Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
6.1 MEDIUM· v3
2.6 LOW· v2
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
1Citrix
1Xenmobile Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
1Citrix
1Xenmobile Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
1Citrix
1Federated Authentication Service
Jun 17, 2026
Mar 10, 2022
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store t...Show more
Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.Show less
1Citrix
1Workspace
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation.
1Citrix
3Application Delivery Controller Firmware
GatewaySd Wan
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a tempora...Show more
An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that could allow an attacker with access to NSIP or SNIP with management interface access to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.Show less
1Citrix
2Application Delivery Controller Firmware
Gateway
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disrupt...Show more
A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when configured as a VPN (Gateway) or AAA virtual server could allow an attacker to cause a temporary disruption of the Management GUI, Nitro API, and RPC communication.Show less
1Citrix
1Sharefile Storagezones Controller
Jun 17, 2026
Sep 23, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.
1Citrix
1Sharefile Storagezones Controller
Jun 17, 2026
Aug 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customer...Show more
An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes the ShareFile file encryption option to become disabled if it had previously been enabled. Customers are only affected by this issue if they previously selected “Enable Encryption” in the ShareFile configuration page and did not re-select this setting after running the CTX269106 mitigation tool. ShareFile customers who have not run the CTX269106 mitigation tool or who re-selected “Enable Encryption” immediately after running the tool are unaffected by this issue.Show less