Cloud Software Group Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Cloud Software Group products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
2
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
Cloud Software Group KEVs Added by Year
4 Cloud Software Group KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-5914
Cross-site scripting (XSS) |
Citrix StoreFront | High | Not in CISA | 26 Dec 2025 |
|
CVE-2023-6548
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to... |
NetScaler ADC, NetScaler Gateway | Confirmed | In CISA | 17 Jan 2024 |
|
CVE-2023-6549
Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of... |
NetScaler ADC | Confirmed | In CISA | 17 Jan 2024 |
|
CVE-2023-6184
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting |
Citrix Session Recording | High | Not in CISA | 18 Jan 2024 |
Common Vulnerability Classes (CWE)
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
- CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') 1
- CWE-913 — Improper Control of Dynamically-Managed Code Resources 1
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology