CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-6151HIGH | Local Privilege escalation allows a low-privileged user to gain SYSTEM privilegesLocal Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and Citrix DaaS CWE-269Jul 10, 2024 | CVSS8.5v4.0 | EPSS0.214% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-6184MEDIUM | Citrix virtual_apps_and_desktops Improper Control of Dynamically-Managed Code ResourcesCross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | CVSS5.0v3.1 | EPSS46.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-8283HIGH | Citrix virtual_apps_and_desktops Improper Privilege ManagementAn authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9. CWE-269Dec 14, 2020 | CVSS8.8v3.1 | EPSS2.57% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-8270HIGH | Citrix virtual_apps_and_desktops Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342 CWE-78Nov 16, 2020 | CVSS8.8v3.1 | EPSS3.48% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |
CVE-2020-8269HIGH | Citrix virtual_apps_and_desktops Improper Privilege ManagementAn unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9 CWE-269Nov 16, 2020 | CVSS8.8v3.1 | EPSS2.68% | PoCs0 | SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templates | STIX |