聚合 NVD、CVE 及多源情資,深度解析 RCE 等高危風險。系統整合 CVSS 與 EPSS 模型,動態追蹤 Exploit 資源與 PoC 公開狀態,研判可利用性。結合官方修補與修復方案,優化漏洞管理優先級,縮短回應週期,保障資產安全。
指派機構(CNA / 來源):[email protected] 移除此篩選
| CVE | 描述 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|
| CVE-2023-3467 | Privilege Escalation to root administrator (nsroot) | 8.0 | 1.58% | 2023-07-19 | 2026-06-17 |
| CVE-2023-3466 | Reflected Cross-Site Scripting (XSS) | 8.3 | 2.84% | 2023-07-19 | 2026-06-17 |
| CVE-2023-3519 KEV | Unauthenticated remote code execution | 9.8 | 99.72% | 2023-07-19 | 2026-06-17 |
| CVE-2023-24492 | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts. | 9.6 | 0.88% | 2023-07-11 | 2026-06-17 |
| CVE-2023-24491 | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM. | 7.8 | 0.19% | 2023-07-11 | 2026-06-17 |
| CVE-2023-24490 | Users with only access to launch VDA applications can launch an unauthorized desktop | 6.3 | 0.30% | 2023-07-10 | 2026-06-17 |
| CVE-2023-24489 KEV | A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller. | 9.8 | 95.08% | 2023-07-10 | 2026-06-17 |
| CVE-2023-24488 | Cross site scripting vulnerability in Citrix ADC and Citrix Gateway in allows and attacker to perform cross site scripting | 6.1 | 80.91% | 2023-07-10 | 2026-06-17 |
| CVE-2023-24487 | Arbitrary file read in Citrix ADC and Citrix Gateway | 6.3 | 1.07% | 2023-07-10 | 2026-06-17 |
| CVE-2023-24486 | A vulnerability has been identified in Citrix Workspace app for Linux that, if exploited, may result in a malicious local user being able to gain access to the Citrix Virtual Apps and Desktops session of another user who is using the same computer from which the ICA session is launched. | 5.5 | 0.18% | 2023-07-10 | 2026-06-17 |
| CVE-2023-24485 | Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform operations as SYSTEM on the computer running Citrix Workspace app. | 7.8 | 0.22% | 2023-02-16 | 2026-06-17 |
| CVE-2023-24484 | A malicious user can cause log files to be written to a directory that they do not have permission to write to. | 5.5 | 0.26% | 2023-02-16 | 2026-06-17 |
| CVE-2023-24483 | A vulnerability has been identified that, if exploited, could result in a local user elevating their privilege level to NT AUTHORITY\SYSTEM on a Citrix Virtual Apps and Desktops Windows VDA. | 7.8 | 0.27% | 2023-02-16 | 2026-06-17 |
| CVE-2022-27508 | Unauthenticated denial of service | 7.5 | 1.01% | 2023-01-26 | 2026-06-17 |
| CVE-2022-27507 | Authenticated denial of service | 6.5 | 0.98% | 2023-01-26 | 2026-06-17 |
| CVE-2022-27518 KEV | Unauthenticated remote arbitrary code execution | 9.8 | 6.93% | 2022-12-13 | 2026-06-17 |
| CVE-2022-27516 | User login brute force protection functionality bypass | 5.3 | 0.60% | 2022-11-08 | 2026-06-17 |
| CVE-2022-27513 | Remote desktop takeover via phishing | 8.3 | 0.27% | 2022-11-08 | 2026-06-17 |
| CVE-2022-27510 | Unauthorized access to Gateway user capabilities | 9.8 | 1.18% | 2022-11-08 | 2026-06-17 |
| CVE-2022-27509 | Unauthenticated redirection to a malicious website | 6.1 | 0.38% | 2022-07-28 | 2026-06-17 |