Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-23756 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not … Helpdesk 4.99.9+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-23757 GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly t… Helpdesk 4.99.10+ Fix from $1,6002026-04-20 MEDIUM 5.4 CVE-2026-23758 GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members t… Helpdesk 4.99.9+ Fix from $1,6002026-04-20 CRITICAL 9.8 CVE-2026-2038 GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication… Archiver Mitigation only Fix from $2,3002026-02-20 CRITICAL 9.8 CVE-2026-2039 GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio… Archiver Mitigation only Fix from $2,3002026-02-20 HIGH 8.8 CVE-2026-2036 GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute … Archiver Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2037 GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a… Archiver Mitigation only Fix from $1,9502026-02-20 MEDIUM 5.4 CVE-2026-23616 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenti… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23617 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions inter… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23618 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions in… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23619 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23613 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An auth… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23614 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interfa… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23615 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions inte… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23608 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An au… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23609 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23610 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authe… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23611 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist management page. An authenticate… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23612 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist configuration page. An authe… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23604 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An … Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23605 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. … Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23606 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation work… Mailessentials 22.4+ Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-23607 GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitelist management interface. An … Mailessentials 22.4+ Fix from $1,6002026-02-19 CRITICAL 9.8 CVE-2025-34069 An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the G… Kerio Control Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-34070 A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privil… Kerio Control Mitigation only Fix from $2,3002025-07-02 CRITICAL 9.8 CVE-2025-34071 A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code thr… Kerio Control Mitigation only Fix from $2,3002025-07-02 HIGH 8.8 CVE-2025-34491 GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary cod… Mailessentials 21.8+ Fix from $1,9502025-04-28 MEDIUM 6.5 CVE-2025-34490 GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H… Mailessentials 21.8+ Fix from $1,6002025-04-28 HIGH 7.8 CVE-2025-34489 GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by… Mailessentials 21.8+ Fix from $1,9502025-04-28 MEDIUM 5.4 CVE-2025-2976 A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown function of the component File Up… Kerio Connect No fix yet Fix from $1,6002025-03-31