Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2024-7889 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 7.0 | 0.25% | 2024-09-11 | 2024-10-22 |
| CVE-2024-7890 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows | 5.4 | 0.18% | 2024-09-11 | 2024-10-22 |
| CVE-2022-26355 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS adminis | 4.4 | 0.17% | 2022-03-10 | 2024-11-21 |
| CVE-2022-27503 | Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 | 6.1 | 0.45% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27505 | Reflected cross site scripting (XSS) | 6.1 | 0.50% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27506 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI | 2.7 | 0.61% | 2022-04-13 | 2024-11-21 |
| CVE-2022-27509 | Unauthenticated redirection to a malicious website | 6.1 | 0.38% | 2022-07-28 | 2024-11-21 |
| CVE-2022-27510 | Unauthorized access to Gateway user capabilities | 9.8 | 1.18% | 2022-11-08 | 2024-11-21 |
| CVE-2022-27511 | Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted. | 8.1 | 12.05% | 2022-06-16 | 2024-11-21 |
| CVE-2022-27512 | Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | 5.3 | 0.88% | 2022-06-16 | 2024-11-21 |
| CVE-2022-27513 | Remote desktop takeover via phishing | 8.3 | 0.27% | 2022-11-08 | 2024-11-21 |
| CVE-2022-27516 | User login brute force protection functionality bypass | 5.3 | 0.60% | 2022-11-08 | 2024-11-21 |
| CVE-2023-24486 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | 5.5 | 0.18% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24487 | Arbitrary file read in Citrix ADC and Citrix Gateway | 6.3 | 1.07% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24488 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | 6.1 | 80.91% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24490 | Users with only access to launch VDA applications can launch an unauthorized desktop | 6.3 | 0.30% | 2023-07-10 | 2024-11-21 |
| CVE-2023-24491 | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM. | 7.8 | 0.19% | 2023-07-11 | 2024-11-21 |
| CVE-2023-24492 | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts. | 9.6 | 0.82% | 2023-07-11 | 2024-11-21 |
| CVE-2023-3466 | Reflected Cross-Site Scripting (XSS) | 8.3 | 3.04% | 2023-07-19 | 2024-11-21 |
| CVE-2023-3467 | Privilege Escalation to root administrator (nsroot) | 8.0 | 2.10% | 2023-07-19 | 2024-11-21 |