Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-24782 Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be explo… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 HIGH 8.2 CVE-2026-24752 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-24753 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-24754 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a stored XSS vulnerability in Kiteworks Secure Data Forms could allow an authentic… Kiteworks 9.3.0+ Fix from $1,6002026-06-01 MEDIUM 5.4 CVE-2026-24755 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 HIGH 8.2 CVE-2026-24751 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an extern… Kiteworks 9.3.0+ Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-23638 Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerability in Kiteworks Secure Data … Kiteworks 9.3.0+ Fix from $1,6002026-06-01 HIGH 7.5 CVE-2026-29092 Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows bl… Kiteworks 9.2.1+ Fix from $1,9502026-03-25 HIGH 7.2 CVE-2026-23636 Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, the manager of a form could potentially exploit an … Kiteworks 9.2.1+ Fix from $1,9502026-03-25 MEDIUM 6.5 CVE-2026-23635 Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of the security attributes could… Kiteworks 9.2.1+ Fix from $1,6002026-03-25 MEDIUM 5.4 CVE-2026-24750 Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attacker could exploit an Improper… Kiteworks 9.2.1+ Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-23514 Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerability that allows authenticated … Kiteworks Mitigation only Fix from $1,6002026-03-25 HIGH 7.2 CVE-2026-28270 Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files wit… Kiteworks 9.2.0+ Fix from $1,9502026-02-27 MEDIUM 6.5 CVE-2026-28271 Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF … Kiteworks 9.2.0+ Fix from $1,6002026-02-27 HIGH 8.8 CVE-2026-28269 Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated u… Kiteworks 9.2.0+ Fix from $1,9502026-02-26 HIGH 8.8 CVE-2025-53939 Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to une… Kiteworks 9.1.0+ Fix from $1,9502025-11-29 HIGH 8.8 CVE-2025-53900 Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kitewor… Kiteworks Managed File Transfer 9.1.0+ Fix from $1,9502025-11-29 HIGH 8.1 CVE-2025-53896 Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances… Kiteworks Managed File Transfer 9.1.0+ Fix from $1,9502025-11-29 HIGH 7.2 CVE-2025-53899 Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly … Kiteworks Managed File Transfer 9.1.0+ Fix from $1,9502025-11-29 MEDIUM 6.8 CVE-2025-53897 Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain ac… Kiteworks Managed File Transfer 9.1.0+ Fix from $1,6002025-11-29 MEDIUM 6.5 CVE-2022-24110 Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later. Managed File Transfer 7.6+ Fix from $1,6002022-02-14 HIGH 8.8 CVE-2021-31586EPSS 44% Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. Kiteworks 7.4.0+ Fix from $1,9502021-06-23 MEDIUM 6.7 CVE-2021-31585 Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access. Kiteworks 7.3.1+ Fix from $1,6002021-06-23 CRITICAL 9.8 CVE-2021-27730 Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_4… Fta after 9_12_432 Fix from $2,3002021-03-02 MEDIUM 6.1 CVE-2021-27731 Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and lat… Fta after 9_12_432 Fix from $1,6002021-03-02 CRITICAL 9.8 CVE-2021-27101 KEVEPSS 6% Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FT… Fta after 9_12_370 Fix from $2,3002021-02-16 CRITICAL 9.8 CVE-2021-27103 KEVEPSS 11% Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. Fta 9_12_416+ Fix from $2,3002021-02-16 CRITICAL 9.8 CVE-2021-27104 KEVEPSS 56% Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FT… Fta after 9_12_370 Fix from $2,3002021-02-16 HIGH 7.8 CVE-2021-27102 KEV Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Fta after 9_12_411 Fix from $1,9502021-02-16 CRITICAL 9.8 CVE-2019-5622 Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials. File Transfer Appliance No fix yet Fix from $2,3002020-04-29