CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8451HIGH | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP CWE-125Jun 30, 2026 | CVSS8.8v4.0 | EPSS15.7% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3055CRITICAL | Insufficient input validation leading to memory overreadInsufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | CVSS9.3v4.0 | EPSS84.5% | PoCs7 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-7775CRITICAL | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of ServiceMemory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS an… CWE-119Aug 26, 2025 | CVSS9.2v4.0 | EPSS19.6% | PoCs5 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6543CRITICAL | Memory overflow vulnerability leading to unintended control flow and Denial of ServiceMemory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server CWE-119Jun 25, 2025 | CVSS9.2v4.0 | EPSS10.1% | PoCs3 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-5777CRITICAL | NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overreadInsufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | CVSS9.3v4.0 | EPSS>99.9% | PoCs28 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2024-6235CRITICAL | Sensitive information disclosureSensitive information disclosure in NetScaler Console | CVSS9.4v4.0 | EPSS21.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-6549HIGH | Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow VulnerabilityImproper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read | CVSS8.2v3.1 | EPSS57.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-6548MEDIUM | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityImproper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface. CWE-94Jan 17, 2024 | CVSS5.5v3.1 | EPSS3.19% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4967HIGH | Denial of serviceDenial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server CWE-119Oct 27, 2023 | CVSS8.2v3.1 | EPSS0.885% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2023-4966CRITICAL | Unauthenticated sensitive information disclosureSensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. | CVSS9.4v3.1 | EPSS>99.9% | PoCs15 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2023-3467HIGH | Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege EscalationPrivilege Escalation to root administrator (nsroot) CWE-269Jul 19, 2023 | CVSS8.0v3.1 | EPSS1.53% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3466HIGH | Citrix NetScaler ADC and NetScaler Gateway Improper Input ValidationReflected Cross-Site Scripting (XSS) | CVSS8.3v3.1 | EPSS2.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3519CRITICAL | Citrix NetScaler ADC and NetScaler Gateway Code Injection VulnerabilityUnauthenticated remote code execution | CVSS9.8v3.1 | EPSS99.7% | PoCs17 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2022-27518CRITICAL | Unauthenticated remote arbitrary code executionUnauthenticated remote arbitrary code execution CWE-664Dec 13, 2022 | CVSS9.8v3.1 | EPSS6.88% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2016-4945MEDIUM | Citrix NetScaler ADC and NetScaler Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie. CWE-79Jun 1, 2016 | CVSS6.1v3.0 | EPSS1.37% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |