Skip to content
Noroxi

Citrix records

466 published records for vendor citrix.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

466 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    citrix · application delivery controller firmwareDec 27, 2019

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Unauthenticated remote code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerJul 19, 2023

  • A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    citrix · sharefile storage zones controllerJul 10, 2023

  • NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread

    CriticalCVSS 9.3KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerJun 17, 2025

  • Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    citrix · netscaler sd-wanJul 16, 2019

  • Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID

    CriticalCVSS 9.8KEVWeaponizedEPSS 73%

    citrix · netscaler sd-wanJul 20, 2017

  • Unauthenticated sensitive information disclosure

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerOct 10, 2023

  • Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

    HighCVSS 8.8KEVWeaponizedEPSS 74%

    citrix · netscaler sd-wanJul 16, 2019

  • Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro

    CriticalCVSS 9.8KEVWeaponizedEPSS 54%

    citrix · sharefile storagezones controllerSep 23, 2021

  • Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C

    MediumCVSS 6.5KEVWeaponizedEPSS 88%

    citrix · application delivery controller firmwareJul 10, 2020

  • CVE-2023-6549
    77This week

    Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial

    HighCVSS 7.5KEVWeaponizedEPSS 58%

    citrix · netscaler application delivery controllerJan 17, 2024

  • CVE-2025-7775
    72This week

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service

    CriticalCVSS 9.2KEVWeaponizedEPSS 20%

    citrix · netscaler application delivery controllerAug 26, 2025

  • CVE-2019-11634
    71This week

    Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

    CriticalCVSS 9.8KEVWeaponizedEPSS 8%

    citrix · receiverMay 22, 2019

  • CVE-2022-27518
    71This week

    Unauthenticated remote arbitrary code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 7%

    citrix · application delivery controller firmwareDec 13, 2022

  • CVE-2019-13608
    69This week

    Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

    HighCVSS 7.5KEVWeaponizedEPSS 30%

    citrix · storefront serverAug 29, 2019

  • CVE-2025-6543
    69This week

    Memory overflow vulnerability leading to unintended control flow and Denial of Service

    CriticalCVSS 9.2KEVWeaponizedEPSS 11%

    citrix · netscaler application delivery controllerJun 25, 2025

  • CVE-2026-19490
    69This week

    NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

    CriticalCVSS 9.3KEVWeaponizedEPSS 7%

    citrix · netscaler application delivery controllerAug 19, 2026

  • CVE-2026-3055
    68This week

    Insufficient input validation leading to memory overread

    CriticalCVSS 9.3KEVWeaponizedEPSS 4%

    citrix · netscaler application delivery controllerMar 23, 2026

  • CVE-2026-88772
    68This week

    Memory overflow vulnerability leading to Remote Code Execution or Denial of Service

    CriticalCVSS 9.5KEVWeaponizedEPSS 1%

    citrix · netscaler application delivery controller2 days ago

  • CVE-2026-88771
    68This week

    A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands

    CriticalCVSS 9.5KEVWeaponizedEPSS 1%

    citrix · netscaler application delivery controller2 days ago

  • CVE-2020-8195
    66This week

    Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and

    MediumCVSS 6.5KEVWeaponizedEPSS 33%

    citrix · application delivery controller firmwareJul 10, 2020

  • CVE-2023-6548
    66This week

    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLI

    HighCVSS 8.8KEVWeaponizedEPSS 3%

    citrix · netscaler application delivery controllerJan 17, 2024

  • CVE-2026-8452
    65This week

    Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service

    HighCVSS 8.8KEVWeaponizedEPSS 1%

    citrix · netscaler application delivery controllerJun 30, 2026