Citrix records
466 published records for vendor citrix.
Researcher profile
- Entered KEV
- 28 · 6%
- Weaponized
- 34 · 7.3%
- Pre-auth RCE
- 54
- With a fix record
- 30%
- Median publish → KEV
- 120 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer29
- CWE-20 Improper Input Validation28
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-264 Permissions, Privileges, and Access Controls25
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor23
- CWE-269 Improper Privilege Management21
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
466 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2019-19781Weaponized | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Critical9.8 | KEV | 100.0% | Dec 27, 2019 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2023-3519Weaponized | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Critical9.8 | KEV | 99.7% | Jul 19, 2023 |
98Now | CVE-2023-24489Weaponized | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentcitrix · sharefile storage zones controller · CWE-284 | Critical9.8 | KEV | 97.3% | Jul 10, 2023 |
97Now | CVE-2025-5777Weaponized | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Critical9.3 | KEV | 100.0% | Jun 17, 2025 |
97Now | CVE-2019-12989Weaponized | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.citrix · netscaler sd-wan · CWE-89 | Critical9.8 | KEV | 95.0% | Jul 16, 2019 |
91Now | CVE-2017-6316Weaponized | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID citrix · netscaler sd-wan | Critical9.8 | KEV | 73.0% | Jul 20, 2017 |
90Now | CVE-2023-4966Weaponized | Unauthenticated sensitive information disclosurecitrix · netscaler application delivery controller · CWE-119 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
87Now | CVE-2019-12991Weaponized | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).citrix · netscaler sd-wan · CWE-78 | High8.8 | KEV | 74.1% | Jul 16, 2019 |
85Now | CVE-2021-22941Weaponized | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely comprocitrix · sharefile storagezones controller · CWE-284 | Critical9.8 | KEV | 53.6% | Sep 23, 2021 |
83Now | CVE-2020-8193Weaponized | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Ccitrix · application delivery controller firmware · CWE-284 | Medium6.5 | KEV | 88.4% | Jul 10, 2020 |
77This week | CVE-2023-6549Weaponized | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denialcitrix · netscaler application delivery controller · CWE-119 | High7.5 | KEV | 57.6% | Jan 17, 2024 |
72This week | CVE-2025-7775Weaponized | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Critical9.2 | KEV | 19.6% | Aug 26, 2025 |
71This week | CVE-2019-11634Weaponized | Citrix Workspace App before 1904 for Windows has Incorrect Access Control.citrix · receiver · CWE-284 | Critical9.8 | KEV | 8.0% | May 22, 2019 |
71This week | CVE-2022-27518Weaponized | Unauthenticated remote arbitrary code executioncitrix · application delivery controller firmware · CWE-664 | Critical9.8 | KEV | 6.7% | Dec 13, 2022 |
69This week | CVE-2019-13608Weaponized | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.citrix · storefront server · CWE-611 | High7.5 | KEV | 30.0% | Aug 29, 2019 |
69This week | CVE-2025-6543Weaponized | Memory overflow vulnerability leading to unintended control flow and Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Critical9.2 | KEV | 10.6% | Jun 25, 2025 |
69This week | CVE-2026-19490Weaponized | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490citrix · netscaler application delivery controller · CWE-288 | Critical9.3 | KEV | 7.0% | Aug 19, 2026 |
68This week | CVE-2026-3055Weaponized | Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Critical9.3 | KEV | 4.0% | Mar 23, 2026 |
68This week | CVE-2026-88772Weaponized | Memory overflow vulnerability leading to Remote Code Execution or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Critical9.5 | KEV | 1.3% | 2 days ago |
68This week | CVE-2026-88771Weaponized | A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandscitrix · netscaler application delivery controller · CWE-20 | Critical9.5 | KEV | 1.1% | 2 days ago |
66This week | CVE-2020-8195Weaponized | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 andcitrix · application delivery controller firmware · CWE-20 | Medium6.5 | KEV | 33.0% | Jul 10, 2020 |
66This week | CVE-2023-6548Weaponized | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIcitrix · netscaler application delivery controller · CWE-94 | High8.8 | KEV | 3.2% | Jan 17, 2024 |
65This week | CVE-2026-8452Weaponized | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | High8.8 | KEV | 1.0% | Jun 30, 2026 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2019-1978199Now
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · application delivery controller firmwareDec 27, 2019
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2023-351999Now
Unauthenticated remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerJul 19, 2023
- CVE-2023-2448998Now
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent
CriticalCVSS 9.8KEVWeaponizedEPSS 97%citrix · sharefile storage zones controllerJul 10, 2023
- CVE-2025-577797Now
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
CriticalCVSS 9.3KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerJun 17, 2025
- CVE-2019-1298997Now
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%citrix · netscaler sd-wanJul 16, 2019
- CVE-2017-631691Now
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID
CriticalCVSS 9.8KEVWeaponizedEPSS 73%citrix · netscaler sd-wanJul 20, 2017
- CVE-2023-496690Now
Unauthenticated sensitive information disclosure
HighCVSS 7.5KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerOct 10, 2023
- CVE-2019-1299187Now
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
HighCVSS 8.8KEVWeaponizedEPSS 74%citrix · netscaler sd-wanJul 16, 2019
- CVE-2021-2294185Now
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro
CriticalCVSS 9.8KEVWeaponizedEPSS 54%citrix · sharefile storagezones controllerSep 23, 2021
- CVE-2020-819383Now
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C
MediumCVSS 6.5KEVWeaponizedEPSS 88%citrix · application delivery controller firmwareJul 10, 2020
- CVE-2023-654977This week
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial
HighCVSS 7.5KEVWeaponizedEPSS 58%citrix · netscaler application delivery controllerJan 17, 2024
- CVE-2025-777572This week
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
CriticalCVSS 9.2KEVWeaponizedEPSS 20%citrix · netscaler application delivery controllerAug 26, 2025
- CVE-2019-1163471This week
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
CriticalCVSS 9.8KEVWeaponizedEPSS 8%citrix · receiverMay 22, 2019
- CVE-2022-2751871This week
Unauthenticated remote arbitrary code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 7%citrix · application delivery controller firmwareDec 13, 2022
- CVE-2019-1360869This week
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
HighCVSS 7.5KEVWeaponizedEPSS 30%citrix · storefront serverAug 29, 2019
- CVE-2025-654369This week
Memory overflow vulnerability leading to unintended control flow and Denial of Service
CriticalCVSS 9.2KEVWeaponizedEPSS 11%citrix · netscaler application delivery controllerJun 25, 2025
- CVE-2026-1949069This week
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
CriticalCVSS 9.3KEVWeaponizedEPSS 7%citrix · netscaler application delivery controllerAug 19, 2026
- CVE-2026-305568This week
Insufficient input validation leading to memory overread
CriticalCVSS 9.3KEVWeaponizedEPSS 4%citrix · netscaler application delivery controllerMar 23, 2026
- CVE-2026-8877268This week
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
CriticalCVSS 9.5KEVWeaponizedEPSS 1%citrix · netscaler application delivery controller2 days ago
- CVE-2026-8877168This week
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
CriticalCVSS 9.5KEVWeaponizedEPSS 1%citrix · netscaler application delivery controller2 days ago
- CVE-2020-819566This week
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and
MediumCVSS 6.5KEVWeaponizedEPSS 33%citrix · application delivery controller firmwareJul 10, 2020
- CVE-2023-654866This week
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLI
HighCVSS 8.8KEVWeaponizedEPSS 3%citrix · netscaler application delivery controllerJan 17, 2024
- CVE-2026-845265This week
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
HighCVSS 8.8KEVWeaponizedEPSS 1%citrix · netscaler application delivery controllerJun 30, 2026