Записи Citrix
466 опубликованных записей вендора citrix.
Профиль для исследователя
- Попали в KEV
- 28 · 6 %
- С эксплойтом
- 34 · 7,3 %
- Pre-auth RCE
- 54
- С записью об исправлении
- 30 %
- Медиана: публикация → KEV
- 120 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer29
- CWE-20 Improper Input Validation28
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-264 Permissions, Privileges, and Access Controls25
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor23
- CWE-269 Improper Privilege Management21
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
466 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2019-19781Готовый эксплойт | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Критическая9,8 | KEV | 100,0 % | 27 дек. 2019 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2023-3519Готовый эксплойт | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Критическая9,8 | KEV | 99,7 % | 19 июл. 2023 г. |
98Срочно | CVE-2023-24489Готовый эксплойт | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthentcitrix · sharefile storage zones controller · CWE-284 | Критическая9,8 | KEV | 97,3 % | 10 июл. 2023 г. |
97Срочно | CVE-2025-5777Готовый эксплойт | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Критическая9,3 | KEV | 100,0 % | 17 июн. 2025 г. |
97Срочно | CVE-2019-12989Готовый эксплойт | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.citrix · netscaler sd-wan · CWE-89 | Критическая9,8 | KEV | 95,0 % | 16 июл. 2019 г. |
91Срочно | CVE-2017-6316Готовый эксплойт | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID citrix · netscaler sd-wan | Критическая9,8 | KEV | 73,0 % | 20 июл. 2017 г. |
90Срочно | CVE-2023-4966Готовый эксплойт | Unauthenticated sensitive information disclosurecitrix · netscaler application delivery controller · CWE-119 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
87Срочно | CVE-2019-12991Готовый эксплойт | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).citrix · netscaler sd-wan · CWE-78 | Высокая8,8 | KEV | 74,1 % | 16 июл. 2019 г. |
85Срочно | CVE-2021-22941Готовый эксплойт | Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely comprocitrix · sharefile storagezones controller · CWE-284 | Критическая9,8 | KEV | 53,6 % | 23 сент. 2021 г. |
83Срочно | CVE-2020-8193Готовый эксплойт | Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Ccitrix · application delivery controller firmware · CWE-284 | Средняя6,5 | KEV | 88,4 % | 10 июл. 2020 г. |
77На этой неделе | CVE-2023-6549Готовый эксплойт | Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denialcitrix · netscaler application delivery controller · CWE-119 | Высокая7,5 | KEV | 57,6 % | 17 янв. 2024 г. |
72На этой неделе | CVE-2025-7775Готовый эксплойт | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Критическая9,2 | KEV | 19,6 % | 26 авг. 2025 г. |
71На этой неделе | CVE-2019-11634Готовый эксплойт | Citrix Workspace App before 1904 for Windows has Incorrect Access Control.citrix · receiver · CWE-284 | Критическая9,8 | KEV | 8,0 % | 22 мая 2019 г. |
71На этой неделе | CVE-2022-27518Готовый эксплойт | Unauthenticated remote arbitrary code executioncitrix · application delivery controller firmware · CWE-664 | Критическая9,8 | KEV | 6,7 % | 13 дек. 2022 г. |
69На этой неделе | CVE-2019-13608Готовый эксплойт | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.citrix · storefront server · CWE-611 | Высокая7,5 | KEV | 30,0 % | 29 авг. 2019 г. |
69На этой неделе | CVE-2025-6543Готовый эксплойт | Memory overflow vulnerability leading to unintended control flow and Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Критическая9,2 | KEV | 10,6 % | 25 июн. 2025 г. |
69На этой неделе | CVE-2026-19490Готовый эксплойт | NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490citrix · netscaler application delivery controller · CWE-288 | Критическая9,3 | KEV | 7,0 % | 19 авг. 2026 г. |
68На этой неделе | CVE-2026-3055Готовый эксплойт | Insufficient input validation leading to memory overreadcitrix · netscaler application delivery controller · CWE-125 | Критическая9,3 | KEV | 4,0 % | 23 мар. 2026 г. |
68На этой неделе | CVE-2026-88772Готовый эксплойт | Memory overflow vulnerability leading to Remote Code Execution or Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Критическая9,5 | KEV | 1,3 % | 3 дня назад |
68На этой неделе | CVE-2026-88771Готовый эксплойт | A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commandscitrix · netscaler application delivery controller · CWE-20 | Критическая9,5 | KEV | 1,1 % | 3 дня назад |
66На этой неделе | CVE-2020-8195Готовый эксплойт | Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 andcitrix · application delivery controller firmware · CWE-20 | Средняя6,5 | KEV | 33,0 % | 10 июл. 2020 г. |
66На этой неделе | CVE-2023-6548Готовый эксплойт | Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIcitrix · netscaler application delivery controller · CWE-94 | Высокая8,8 | KEV | 3,2 % | 17 янв. 2024 г. |
65На этой неделе | CVE-2026-8452Готовый эксплойт | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Servicecitrix · netscaler application delivery controller · CWE-119 | Высокая8,8 | KEV | 1,0 % | 30 июн. 2026 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2019-1978199Срочно
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · application delivery controller firmware27 дек. 2019 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2023-351999Срочно
Unauthenticated remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller19 июл. 2023 г.
- CVE-2023-2448998Срочно
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthent
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %citrix · sharefile storage zones controller10 июл. 2023 г.
- CVE-2025-577797Срочно
NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller17 июн. 2025 г.
- CVE-2019-1298997Срочно
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %citrix · netscaler sd-wan16 июл. 2019 г.
- CVE-2017-631691Срочно
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 73 %citrix · netscaler sd-wan20 июл. 2017 г.
- CVE-2023-496690Срочно
Unauthenticated sensitive information disclosure
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller10 окт. 2023 г.
- CVE-2019-1299187Срочно
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 74 %citrix · netscaler sd-wan16 июл. 2019 г.
- CVE-2021-2294185Срочно
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compro
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 54 %citrix · sharefile storagezones controller23 сент. 2021 г.
- CVE-2020-819383Срочно
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and C
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 88 %citrix · application delivery controller firmware10 июл. 2020 г.
- CVE-2023-654977На этой неделе
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 58 %citrix · netscaler application delivery controller17 янв. 2024 г.
- CVE-2025-777572На этой неделе
Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 20 %citrix · netscaler application delivery controller26 авг. 2025 г.
- CVE-2019-1163471На этой неделе
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 8 %citrix · receiver22 мая 2019 г.
- CVE-2022-2751871На этой неделе
Unauthenticated remote arbitrary code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 7 %citrix · application delivery controller firmware13 дек. 2022 г.
- CVE-2019-1360869На этой неделе
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 30 %citrix · storefront server29 авг. 2019 г.
- CVE-2025-654369На этой неделе
Memory overflow vulnerability leading to unintended control flow and Denial of Service
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 11 %citrix · netscaler application delivery controller25 июн. 2025 г.
- CVE-2026-1949069На этой неделе
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 7 %citrix · netscaler application delivery controller19 авг. 2026 г.
- CVE-2026-305568На этой неделе
Insufficient input validation leading to memory overread
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 4 %citrix · netscaler application delivery controller23 мар. 2026 г.
- CVE-2026-8877268На этой неделе
Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 1 %citrix · netscaler application delivery controller3 дня назад
- CVE-2026-8877168На этой неделе
A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands
КритическаяCVSS 9,5KEVГотовый эксплойтEPSS 1 %citrix · netscaler application delivery controller3 дня назад
- CVE-2020-819566На этой неделе
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 33 %citrix · application delivery controller firmware10 июл. 2020 г.
- CVE-2023-654866На этой неделе
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLI
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %citrix · netscaler application delivery controller17 янв. 2024 г.
- CVE-2026-845265На этой неделе
Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 1 %citrix · netscaler application delivery controller30 июн. 2026 г.