Filtered by vendor Fortra
Subscriptions
Total
28 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-6253 | 1 Fortra | 1 Digital Guardian Agent | 2025-02-13 | 6.0 Medium |
| A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file. | ||||
| CVE-2024-25156 | 1 Fortra | 1 Goanywhere Managed File Transfer | 2025-01-23 | 6.5 Medium |
| A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients. | ||||
| CVE-2024-25154 | 1 Fortra | 1 Filecatalyst Direct | 2025-01-21 | 5.3 Medium |
| Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage. | ||||
| CVE-2024-25155 | 1 Fortra | 1 Filecatalyst Direct | 2025-01-21 | 7.2 High |
| In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag. | ||||
| CVE-2021-26837 | 1 Fortra | 1 Delivernow | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information. | ||||
| CVE-2024-8264 | 1 Fortra | 2 Robot Schedule, Robot Schedule Enterprise | 2024-10-17 | 5.5 Medium |
| Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled. | ||||
| CVE-2024-6632 | 1 Fortra | 1 Filecatalyst Workflow | 2024-08-30 | 7.2 High |
| A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability. | ||||
| CVE-2024-25157 | 1 Fortra | 1 Goanywhere Managed File Transfer | 2024-08-29 | 6.5 Medium |
| An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification. | ||||
ReportizFlow