Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kiteworks HIGH 8.8
CVE-2026-24782

Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be explo…

Fix: 9.3.0+
Fix from $1,950 2026-06-01
Kiteworks HIGH 8.2
CVE-2026-24752

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…

Fix: 9.3.0+
Fix from $1,950 2026-06-01
Kiteworks MEDIUM 6.5
CVE-2026-24753

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks MEDIUM 5.4
CVE-2026-24754

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authentic…

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks MEDIUM 5.4
CVE-2026-24755

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks HIGH 8.2
CVE-2026-24751

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern…

Fix: 9.3.0+
Fix from $1,950 2026-06-01
Kiteworks MEDIUM 6.5
CVE-2026-23638

Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data …

Fix: 9.3.0+
Fix from $1,600 2026-06-01
Kiteworks HIGH 7.5
CVE-2026-29092

Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows bl…

Fix: 9.2.1+
Fix from $1,950 2026-03-25
Kiteworks HIGH 7.2
CVE-2026-23636

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an …

Fix: 9.2.1+
Fix from $1,950 2026-03-25
Kiteworks MEDIUM 6.5
CVE-2026-23635

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could…

Fix: 9.2.1+
Fix from $1,600 2026-03-25
Kiteworks MEDIUM 5.4
CVE-2026-24750

Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper…

Fix: 9.2.1+
Fix from $1,600 2026-03-25
Kiteworks MEDIUM 6.5
CVE-2026-23514

Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated …

Mitigation only
Fix from $1,600 2026-03-25
Kiteworks HIGH 7.2
CVE-2026-28270

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit…

Fix: 9.2.0+
Fix from $1,950 2026-02-27
Kiteworks MEDIUM 6.5
CVE-2026-28271

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF …

Fix: 9.2.0+
Fix from $1,600 2026-02-27
Kiteworks HIGH 8.8
CVE-2026-28269

Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated u…

Fix: 9.2.0+
Fix from $1,950 2026-02-26
Kiteworks HIGH 8.8
CVE-2025-53939

Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une…

Fix: 9.1.0+
Fix from $1,950 2025-11-29
Kiteworks Managed File Transfer HIGH 8.8
CVE-2025-53900

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kitewor…

Fix: 9.1.0+
Fix from $1,950 2025-11-29
Kiteworks Managed File Transfer HIGH 8.1
CVE-2025-53896

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances…

Fix: 9.1.0+
Fix from $1,950 2025-11-29
Kiteworks Managed File Transfer HIGH 7.2
CVE-2025-53899

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly …

Fix: 9.1.0+
Fix from $1,950 2025-11-29
Kiteworks Managed File Transfer MEDIUM 6.8
CVE-2025-53897

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain ac…

Fix: 9.1.0+
Fix from $1,600 2025-11-29
Managed File Transfer MEDIUM 6.5
CVE-2022-24110

Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later.

Fix: 7.6+
Fix from $1,600 2022-02-14
Kiteworks HIGH 8.8
CVE-2021-31586EPSS 44%

Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.

Fix: 7.4.0+
Fix from $1,950 2021-06-23
Kiteworks MEDIUM 6.7
CVE-2021-31585

Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access.

Fix: 7.3.1+
Fix from $1,600 2021-06-23
Fta CRITICAL 9.8
CVE-2021-27730

Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_4…

Fix: after 9_12_432
Fix from $2,300 2021-03-02
Fta MEDIUM 6.1
CVE-2021-27731

Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and lat…

Fix: after 9_12_432
Fix from $1,600 2021-03-02
Fta CRITICAL 9.8
CVE-2021-27101 KEVEPSS 6%

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FT…

Fix: after 9_12_370
Fix from $2,300 2021-02-16
Fta CRITICAL 9.8
CVE-2021-27103 KEVEPSS 11%

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

Fix: 9_12_416+
Fix from $2,300 2021-02-16
Fta CRITICAL 9.8
CVE-2021-27104 KEVEPSS 56%

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT…

Fix: after 9_12_370
Fix from $2,300 2021-02-16
Fta HIGH 7.8
CVE-2021-27102 KEV

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

Fix: after 9_12_411
Fix from $1,950 2021-02-16
File Transfer Appliance CRITICAL 9.8
CVE-2019-5622

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.

No fix yet
Fix from $2,300 2020-04-29