Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-9862
Fortra's
Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker w…
Core Privileged Access Manager Server
8.1.0.23 / 9.0.0.5+
HIGH 8.8
CVE-2026-9863
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations.…
Core Privileged Access Manager Server
8.1.0.23 / 9.0.0.5+
HIGH 7.3
CVE-2025-14362
The login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is confi…
Goanywhere Managed File Transfer
7.10.0+
MEDIUM 6.5
CVE-2026-1089
User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and…
Goanywhere Managed File Transfer
7.10.0+
MEDIUM 5.4
CVE-2026-0972
HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0.
Note: The title, details, and description of this…
Goanywhere Managed File Transfer
7.10.0+
CRITICAL 9.8
CVE-2025-10035 KEVEPSS 100%
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…
Goanywhere Managed File Transfer
7.6.3 / 7.8.4+
MEDIUM 5.4
CVE-2024-11922
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to tr…
Goanywhere Managed File Transfer
7.8.0+
MEDIUM 5.5
CVE-2024-8264
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed loggi…
Robot Schedule
3.05+
CRITICAL 9.8
CVE-2024-6633
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of the…
Filecatalyst Workflow
5.1.7+
HIGH 7.2
CVE-2024-6632
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which ca…
Filecatalyst Workflow
5.1.7+
MEDIUM 6.5
CVE-2024-25157
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…
Goanywhere Managed File Transfer
7.6.0+
CRITICAL 9.1
CVE-2024-5276EPSS 90%
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of admi…
Filecatalyst Workflow
5.1.6+
HIGH 7.3
CVE-2024-0259
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrit…
Robot Schedule
3.04+
MEDIUM 6.5
CVE-2024-25156
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…
Goanywhere Managed File Transfer
7.4.2+
MEDIUM 6.1
CVE-2024-25155
In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed…
Filecatalyst Direct
3.8.9+
MEDIUM 5.3
CVE-2024-25154
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to retur…
Filecatalyst Direct
3.8.9+
CRITICAL 9.8
CVE-2024-25153EPSS 42%
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp…
Filecatalyst Workflow
5.1.6+
CRITICAL 9.8
CVE-2024-0204EPSS 95%
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Goanywhere Managed File Transfer
7.4.1+
MEDIUM 6.0
CVE-2023-6253
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and …
Digital Guardian Agent
7.9.4+
CRITICAL 9.8
CVE-2021-26837
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute…
Delivernow
1.2.18+
HIGH 7.2
CVE-2023-0669 KEVEPSS 100%
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due t…
Goanywhere Managed File Transfer
7.1.2+