Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 15 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Insufficient input validation leading to memory overread

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

CWE-125Jun 30, 2026
CVSS8.8v4.0EPSS15.7%PoCs4SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Insufficient input validation leading to memory overread

Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread

CWE-125Mar 23, 20261 related artifact
CVSS9.3v4.0EPSS84.5%PoCs7SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service

Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB virtual servers of type (HTTP, SSL or HTTP_QUIC) bound with IPv6 services or servicegroups bound with IPv6 servers (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS an

CWE-119Aug 26, 2025
CVSS9.2v4.0EPSS19.6%PoCs5SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Memory overflow vulnerability leading to unintended control flow and Denial of Service

Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CWE-119Jun 25, 2025
CVSS9.2v4.0EPSS10.1%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

NetScaler ADC and NetScaler Gateway - Insufficient input validation leading to memory overread

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

CWE-125CWE-457CWE-908Jun 17, 20251 related artifact
CVSS9.3v4.0EPSS>99.9%PoCs28SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Sensitive information disclosure

Sensitive information disclosure in NetScaler Console

CWE-287Jul 10, 20241 related artifact
CVSS9.4v4.0EPSS21.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory Read

CWE-119Jan 17, 20241 related artifact
CVSS8.2v3.1EPSS57.6%PoCs0SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

CWE-94Jan 17, 2024
CVSS5.5v3.1EPSS3.19%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Denial of service

Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server

CWE-119Oct 27, 2023
CVSS8.2v3.1EPSS0.885%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Unauthenticated sensitive information disclosure

Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

CWE-119Oct 10, 20231 related artifact
CVSS9.4v3.1EPSS>99.9%PoCs15SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Citrix ADC and Citrix Gateway Root Administrator (nsroot) Privilege Escalation

Privilege Escalation to root administrator (nsroot)

CWE-269Jul 19, 2023
CVSS8.0v3.1EPSS1.53%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Citrix NetScaler ADC and NetScaler Gateway Improper Input Validation

Reflected Cross-Site Scripting (XSS)

CWE-20CWE-79Jul 19, 2023
CVSS8.3v3.1EPSS2.79%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Unauthenticated remote code execution

CWE-94Jul 19, 20231 related artifact
CVSS9.8v3.1EPSS99.7%PoCs17SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Unauthenticated remote arbitrary code execution

Unauthenticated remote arbitrary code execution

CWE-664Dec 13, 2022
CVSS9.8v3.1EPSS6.88%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Citrix NetScaler ADC and NetScaler Gateway Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via the NSC_TMAC cookie.

CWE-79Jun 1, 2016
CVSS6.1v3.0EPSS1.37%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX