Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
accellion vulnerabilities and exploits
(subscribe to this query)
570
VMScore
CVE-2017-9421
Authentication Bypass vulnerability in Accellion kiteworks prior to 2017.01.00 allows remote malicious users to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.
Accellion Kiteworks
578
VMScore
CVE-2021-31586
Accellion Kiteworks prior to 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Accellion Kiteworks
668
VMScore
CVE-2021-27730
Accellion FTA 9_12_432 and previous versions is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
Accellion Fta
383
VMScore
CVE-2021-27731
Accellion FTA 9_12_432 and previous versions is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.
Accellion Fta
445
VMScore
CVE-2016-9499
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Accellion Ftp Server
383
VMScore
CVE-2016-9500
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.
Accellion Ftp Server
641
VMScore
CVE-2016-5662
Accellion Kiteworks appliances before kw2016.03.00 use setuid-root permissions for /opt/bin/cli, which allows local users to gain privileges via unspecified vectors.
Accellion Kiteworks Appliance
383
VMScore
CVE-2016-5663
Multiple cross-site scripting (XSS) vulnerabilities in oauth_callback.php on Accellion Kiteworks appliances before kw2016.03.00 allow remote malicious users to inject arbitrary web script or HTML via the (1) code, (2) error, or (3) error_description parameter.
Accellion Kiteworks Appliance
445
VMScore
CVE-2016-5664
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote malicious users to read files via a crafted URI.
Accellion Kiteworks Appliance
540
VMScore
CVE-2015-2856
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote malicious users to read arbitrary files via a .. (dot dot) in the statecode cookie.
Accellion File Transfer Appliance
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »