Vulnerabilities > Citrix

DATE CVE VULNERABILITY TITLE RISK
2022-07-28 CVE-2022-27509 Open Redirect vulnerability in Citrix Application Delivery Controller Firmware and Gateway
Unauthenticated redirection to a malicious website
network
low complexity
citrix CWE-601
6.1
2022-06-16 CVE-2022-27511 Unspecified vulnerability in Citrix Application Delivery Management
Corruption of the system by a remote, unauthenticated user.
network
high complexity
citrix
8.1
2022-06-16 CVE-2022-27512 Use After Free vulnerability in Citrix Application Delivery Management
Temporary disruption of the ADM license service.
network
low complexity
citrix CWE-416
5.3
2022-05-26 CVE-2022-21827 Improper Privilege Management vulnerability in Citrix Gateway Plug-In 12.158/12.158.15/13.061.48
An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt or delete files as SYSTEM.
local
low complexity
citrix CWE-269
7.1
2022-04-19 CVE-2021-44519 Path Traversal vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.
network
low complexity
citrix CWE-22
8.8
2022-04-13 CVE-2022-27503 Cross-site Scripting vulnerability in Citrix Storefront Server
Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9
network
low complexity
citrix CWE-79
6.1
2022-04-13 CVE-2022-27505 Cross-site Scripting vulnerability in Citrix products
Reflected cross site scripting (XSS)
network
low complexity
citrix CWE-79
6.1
2022-04-13 CVE-2022-27506 Use of Hard-coded Credentials vulnerability in Citrix products
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
network
low complexity
citrix CWE-798
2.7
2022-04-13 CVE-2021-44520 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
network
low complexity
citrix CWE-77
8.8
2022-04-13 CVE-2022-26151 Command Injection vulnerability in Citrix Xenmobile Server 10.13.0/10.14.0
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
network
low complexity
citrix CWE-77
7.2