Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Core Privileged Access Manager Server CRITICAL 9.8
CVE-2026-9862

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w…

Fix: 8.1.0.23 / 9.0.0.5+
Fix from $2,300 2026-06-15
Core Privileged Access Manager Server HIGH 8.8
CVE-2026-9863

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations.…

Fix: 8.1.0.23 / 9.0.0.5+
Fix from $1,950 2026-06-15
Goanywhere Managed File Transfer HIGH 7.3
CVE-2025-14362

The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is confi…

Fix: 7.10.0+
Fix from $1,950 2026-04-21
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2026-1089

User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and…

Fix: 7.10.0+
Fix from $1,600 2026-04-21
Goanywhere Managed File Transfer MEDIUM 5.4
CVE-2026-0972

HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this…

Fix: 7.10.0+
Fix from $1,600 2026-04-21
Goanywhere Managed File Transfer CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

Fix: 7.6.3 / 7.8.4+
Fix from $2,300 2025-09-18
Goanywhere Managed File Transfer MEDIUM 5.4
CVE-2024-11922

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to tr…

Fix: 7.8.0+
Fix from $1,600 2025-04-28
Robot Schedule MEDIUM 5.5
CVE-2024-8264

Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed loggi…

Fix: 3.05+
Fix from $1,600 2024-10-09
Filecatalyst Workflow CRITICAL 9.8
CVE-2024-6633

The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the…

Fix: 5.1.7+
Fix from $2,300 2024-08-27
Filecatalyst Workflow HIGH 7.2
CVE-2024-6632

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which ca…

Fix: 5.1.7+
Fix from $1,950 2024-08-27
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2024-25157

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…

Fix: 7.6.0+
Fix from $1,600 2024-08-14
Filecatalyst Workflow CRITICAL 9.1
CVE-2024-5276EPSS 90%

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of admi…

Fix: 5.1.6+
Fix from $2,300 2024-06-25
Robot Schedule HIGH 7.3
CVE-2024-0259

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrit…

Fix: 3.04+
Fix from $1,950 2024-03-28
Goanywhere Managed File Transfer MEDIUM 6.5
CVE-2024-25156

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…

Fix: 7.4.2+
Fix from $1,600 2024-03-14
Filecatalyst Direct MEDIUM 6.1
CVE-2024-25155

In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed…

Fix: 3.8.9+
Fix from $1,600 2024-03-13
Filecatalyst Direct MEDIUM 5.3
CVE-2024-25154

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to retur…

Fix: 3.8.9+
Fix from $1,600 2024-03-13
Filecatalyst Workflow CRITICAL 9.8
CVE-2024-25153EPSS 42%

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp…

Fix: 5.1.6+
Fix from $2,300 2024-03-13
Goanywhere Managed File Transfer CRITICAL 9.8
CVE-2024-0204EPSS 95%

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Fix: 7.4.1+
Fix from $2,300 2024-01-22
Digital Guardian Agent MEDIUM 6.0
CVE-2023-6253

A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and …

Fix: 7.9.4+
Fix from $1,600 2023-11-22
Delivernow CRITICAL 9.8
CVE-2021-26837

SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute…

Fix: 1.2.18+
Fix from $2,300 2023-09-19
Goanywhere Managed File Transfer HIGH 7.2
CVE-2023-0669 KEVEPSS 100%

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due t…

Fix: 7.1.2+
Fix from $1,950 2023-02-06