Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2023-07-19 CVE-2023-3466 Cross-site Scripting vulnerability in Citrix products
Reflected Cross-Site Scripting (XSS)
network
low complexity
citrix CWE-79
6.1
2023-07-19 CVE-2023-3467 Unspecified vulnerability in Citrix products
Privilege Escalation to root administrator (nsroot)
low complexity
citrix
8.0
2023-07-19 CVE-2023-3519 Code Injection vulnerability in Citrix products
Unauthenticated remote code execution
network
low complexity
citrix CWE-94
critical
9.8
2023-07-11 CVE-2023-24491 Unspecified vulnerability in Citrix Secure Access Client
A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM.
local
low complexity
citrix
7.8
2023-07-11 CVE-2023-24492 Code Injection vulnerability in Citrix Secure Access Client 23.5.1.3
A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.
network
low complexity
citrix CWE-94
8.8
2023-07-10 CVE-2023-24489 Unspecified vulnerability in Citrix Sharefile Storage Zones Controller
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
network
low complexity
citrix
critical
9.8
2023-07-10 CVE-2023-24490 Unspecified vulnerability in Citrix products
Users with only access to launch VDA applications can launch an unauthorized desktop
network
low complexity
citrix
4.3
2023-07-10 CVE-2023-24486 Unspecified vulnerability in Citrix Workspace
A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched.
local
low complexity
citrix
5.5
2023-07-10 CVE-2023-24487 Unspecified vulnerability in Citrix Application Delivery Controller and Gateway
Arbitrary file read in Citrix ADC and Citrix Gateway?
network
low complexity
citrix
7.5
2023-07-10 CVE-2023-24488 Cross-site Scripting vulnerability in Citrix Application Delivery Controller and Gateway
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway? in allows and attacker to perform cross site scripting
network
low complexity
citrix CWE-79
6.1