CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “citrix”

173 vulnerabilities found for “citrix”

Page 1 of 9

CVE-2024-2049
MEDIUM6.5

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the appliance via Access to management IP.

citrix / sd-wan_1000_firmware+17
Network
Published Mar 12, 2024
Page 1 of 9
CVE-2023-24490
MEDIUM6.3

Users with only access to launch VDA applications can launch an unauthorized desktop

citrix / virtual_apps_and_desktops+21
Network
Published Jul 10, 2023
CVE-2021-44519
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

citrix / xenmobile_server+8
Network
Published Apr 19, 2022
CVE-2022-27506
LOW2.7

Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI

citrix / sd-wan_110_firmware+19
Network
Published Apr 13, 2022
CVE-2022-26151
HIGH7.2

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

citrix / xenmobile_server+10
Network
Published Apr 13, 2022
CVE-2021-44520
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

citrix / xenmobile_server+8
Network
Published Apr 13, 2022
CVE-2022-27505
MEDIUM6.1

Reflected cross site scripting (XSS)

citrix / sd-wan_110_firmware+17
Network
Published Apr 13, 2022
CVE-2021-22928
HIGH7.8

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

citrix / virtual_apps_and_desktops+8
Local
Published Aug 5, 2021
CVE-2021-22914
HIGH7.5

Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installation log files. Such information could be used by an malicious actor to access a Citrix Cloud environment. This issue affects all versions of Citrix Cloud Connector that were installed by passing secure client parameters for installation via the command line. The issue does not affect Citrix Cloud Connector if it was installed using the interactive installer or where a parameter file was used with the command-line installer.

citrix / cloud_connector
Network
Published Jun 16, 2021
CVE-2020-8275
MEDIUM4.3

Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

citrix / secure_mail
Network
Published Jan 6, 2021
CVE-2020-8274
MEDIUM6.5

Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device or a threat actor would need to execute arbitrary code on the Android device.

citrix / secure_mail
Network
Published Jan 6, 2021
CVE-2020-8283
HIGH8.8

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

citrix / virtual_apps_and_desktops+13
Network
Published Dec 14, 2020
CVE-2020-8269
HIGH8.8

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

citrix / virtual_apps_and_desktops+13
Network
Published Nov 16, 2020
CVE-2020-8253
HIGH7.5

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

citrix / xenmobile_server+17
Network
Published Sep 18, 2020
CVE-2020-8209
HIGH7.5

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2020-8210
HIGH7.5

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2020-8212
CRITICAL9.8

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

citrix / xenmobile_server+15
Network
Published Aug 17, 2020
CVE-2020-8211
CRITICAL9.8

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2020-8208
MEDIUM6.1

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2018-10648
CRITICAL9.8

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018