Vulnerabilities > Citrix > High

DATE CVE VULNERABILITY TITLE RISK
2020-08-17 CVE-2020-8212 Incorrect Authorization vulnerability in Citrix Xenmobile Server
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.
network
low complexity
citrix CWE-863
7.5
2020-08-17 CVE-2020-8211 SQL Injection vulnerability in Citrix Xenmobile Server
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
network
low complexity
citrix CWE-89
7.5
2020-06-08 CVE-2020-13885 Incorrect Default Permissions vulnerability in Citrix Workspace APP 1909/1911/2002
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
local
low complexity
citrix CWE-276
7.2
2020-06-08 CVE-2020-13884 Incorrect Default Permissions vulnerability in Citrix Workspace APP 1909/1911/2002
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
local
low complexity
citrix CWE-276
7.2
2020-03-06 CVE-2020-10111 HTTP Request Smuggling vulnerability in Citrix Gateway Firmware 11.1/12.0/12.1
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests.
network
low complexity
citrix CWE-444
7.5
2019-10-21 CVE-2019-18225 Unspecified vulnerability in Citrix products
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28.
network
low complexity
citrix
7.5
2019-07-16 CVE-2019-12989 SQL Injection vulnerability in Citrix Netscaler Sd-Wan and Sd-Wan
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
network
low complexity
citrix CWE-89
7.5
2019-06-05 CVE-2019-9548 Unspecified vulnerability in Citrix Application Delivery Management 12.1
Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
network
low complexity
citrix
7.5
2019-05-22 CVE-2019-11634 Unspecified vulnerability in Citrix Receiver and Workspace
Citrix Workspace App before 1904 for Windows has Incorrect Access Control.
network
low complexity
citrix
7.5
2018-12-08 CVE-2018-19962 Information Exposure vulnerability in multiple products
An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.
local
high complexity
xen debian citrix CWE-200
7.8