Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Helpdesk MEDIUM 5.4
CVE-2026-23756

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not …

Fix: 4.99.9+
Fix from $1,600 2026-04-20
Helpdesk MEDIUM 5.4
CVE-2026-23757

GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly t…

Fix: 4.99.10+
Fix from $1,600 2026-04-20
Helpdesk MEDIUM 5.4
CVE-2026-23758

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members t…

Fix: 4.99.9+
Fix from $1,600 2026-04-20
Archiver CRITICAL 9.8
CVE-2026-2038

GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…

Mitigation only
Fix from $2,300 2026-02-20
Archiver CRITICAL 9.8
CVE-2026-2039

GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticatio…

Mitigation only
Fix from $2,300 2026-02-20
Archiver HIGH 8.8
CVE-2026-2036

GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute …

Mitigation only
Fix from $1,950 2026-02-20
Archiver HIGH 8.8
CVE-2026-2037

GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2026-02-20
Mailessentials MEDIUM 5.4
CVE-2026-23616

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenti…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23617

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Body) conditions inter…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23618

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Spam Keyword Checking (Subject) conditions in…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23619

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Local Domains settings page. An authenticated…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23613

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the URI DNS Blocklist configuration page. An auth…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23614

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework IP Exceptions interfa…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23615

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Sender Policy Framework Email Exceptions inte…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23608

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Mail Monitoring rule creation endpoint. An au…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23609

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Perimeter SMTP Servers configuration page. An…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23610

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the POP2Exchange configuration endpoint. An authe…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23611

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP Blocklist management page. An authenticate…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23612

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the IP DNS Blocklist configuration page. An authe…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23604

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Keyword Filtering rule creation workflow. An …

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23605

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Attachment Filtering rule creation workflow. …

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23606

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Advanced Content Filtering rule creation work…

Fix: 22.4+
Fix from $1,600 2026-02-19
Mailessentials MEDIUM 5.4
CVE-2026-23607

GFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spam Whitelist management interface. An …

Fix: 22.4+
Fix from $1,600 2026-02-19
Kerio Control CRITICAL 9.8
CVE-2025-34069

An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the G…

Mitigation only
Fix from $2,300 2025-07-02
Kerio Control CRITICAL 9.8
CVE-2025-34070

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privil…

Mitigation only
Fix from $2,300 2025-07-02
Kerio Control CRITICAL 9.8
CVE-2025-34071

A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code thr…

Mitigation only
Fix from $2,300 2025-07-02
Mailessentials HIGH 8.8
CVE-2025-34491

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary cod…

Fix: 21.8+
Fix from $1,950 2025-04-28
Mailessentials MEDIUM 6.5
CVE-2025-34490

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H…

Fix: 21.8+
Fix from $1,600 2025-04-28
Mailessentials HIGH 7.8
CVE-2025-34489

GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by…

Fix: 21.8+
Fix from $1,950 2025-04-28
Kerio Connect MEDIUM 5.4
CVE-2025-2976

A vulnerability was found in GFI KerioConnect 10.0.6. It has been classified as problematic. Affected is an unknown function of the component File Up…

No fix yet
Fix from $1,600 2025-03-31