Skip to content

Products › IT administration and security

IT administration and security

Managed file transfer (MFT)

Platforms for exchanging and sharing files with outside parties, often exposed to the internet.

For example: MOVEit, GoAnywhere, CrushFTP, Cleo.

Category RSS feed

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    ownCloud ServerCVE-2023-49105

    ownCloud Improper Authentication Vulnerability

    Hunt for compromise (CISA)CVE from 2023, added in 2026

    CVSS severity 9.8critical

    Added Aug 27, 2026

  2. Rank 2

    Gladinet CentreStack / TriofoxCVE-2025-14611

    Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

    CVSS severity 9.8critical

    Added Dec 15, 2025

  3. Rank 3

    Gladinet CentreStack / TriofoxCVE-2025-12480

    Gladinet Triofox Improper Access Control Vulnerability

    CVSS severity 9.1critical

    Added Nov 12, 2025

  4. Rank 4

    Soliton Systems FileZenCVE-2026-25108

    Soliton Systems K.K FileZen OS Command Injection Vulnerability

    CVSS severity 8.8high

    Added Feb 24, 2026

  5. Rank 5

    SolarWinds Serv-UCVE-2026-28318

    SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability

    CVSS severity 7.5high

    Added Jun 5, 2026

  6. Rank 6

    Gladinet CentreStack / TriofoxCVE-2025-11371

    Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

    CVSS severity 7.5high

    Added Nov 4, 2025

  7. Rank 7

    Wing FTP ServerCVE-2025-47813

    Wing FTP Server Information Disclosure Vulnerability

    CVSS severity 4.3medium

    Added Mar 16, 2026

  8. Rank 8

    Wing FTP ServerCVE-2025-47812

    Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

    CVSS severity 10.0critical

    Added Jul 14, 2025

  9. Rank 9

    CrushFTPCVE-2024-4040

    CrushFTP VFS Sandbox Escape Vulnerability

    CVSS severity 10.0critical

    Added Apr 24, 2024

  10. Rank 10

    SolarWinds Serv-UCVE-2021-35211

    SolarWinds Serv-U Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 10.0critical

    Added Nov 3, 2021

Show 23 more vulnerabilities
  1. Rank 11

    Fortra GoAnywhere MFTCVE-2025-10035

    Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Sep 29, 2025

  2. Rank 12

    CrushFTPCVE-2025-54309

    CrushFTP Unprotected Alternate Channel Vulnerability

    CVSS severity 9.8critical

    Added Jul 22, 2025

  3. Rank 13

    Gladinet CentreStack / TriofoxCVE-2025-30406

    Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

    CVSS severity 9.8critical

    Added Apr 8, 2025

  4. Rank 14

    CrushFTPCVE-2025-31161

    CrushFTP Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Apr 7, 2025

  5. Rank 15

    Cleo Harmony / VLTrader / LexiComCVE-2024-55956

    Cleo Multiple Products Unauthenticated File Upload Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Dec 17, 2024

  6. Rank 16

    Cleo Harmony / VLTrader / LexiComCVE-2024-50623

    Cleo Multiple Products Unrestricted File Upload Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Dec 13, 2024

  7. Rank 17

    ProjectSendCVE-2024-11680

    ProjectSend Improper Authentication Vulnerability

    CVSS severity 9.8critical

    Added Dec 3, 2024

  8. Rank 18

    Rejetto HTTP File Server (HFS)CVE-2024-23692

    Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jul 9, 2024

  9. Rank 19

    Citrix ShareFileCVE-2023-24489

    Citrix Content Collaboration ShareFile Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added Aug 16, 2023

  10. Rank 20

    Progress MOVEit TransferCVE-2023-34362

    Progress MOVEit Transfer SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jun 2, 2023

  11. Rank 21

    IBM Aspera FaspexCVE-2022-47986

    IBM Aspera Faspex Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Feb 21, 2023

  12. Rank 22

    Rejetto HTTP File Server (HFS)CVE-2014-6287

    Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability

    CVE from 2014, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  13. Rank 23

    Citrix ShareFileCVE-2021-22941

    Citrix ShareFile Improper Access Control Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 25, 2022

  14. Rank 24

    Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27101

    Accellion FTA SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  15. Rank 25

    Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27103

    Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  16. Rank 26

    Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27104

    Accellion FTA OS Command Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 3, 2021

  17. Rank 27

    Progress WS_FTP ServerCVE-2023-40044

    Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 8.8high

    Added Oct 5, 2023

  18. Rank 28

    Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27102

    Accellion FTA OS Command Injection Vulnerability

    Ransomware

    CVSS severity 7.8high

    Added Nov 3, 2021

  19. Rank 29

    North Grid ProselfCVE-2023-45727

    North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability

    CVSS severity 7.5high

    Added Dec 3, 2024

  20. Rank 30

    SolarWinds Serv-UCVE-2024-28995

    SolarWinds Serv-U Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Jul 17, 2024

  21. Rank 31

    ownCloud ServerCVE-2023-49103

    ownCloud graphapi Information Disclosure Vulnerability

    CVSS severity 7.5high

    Added Nov 30, 2023

  22. Rank 32

    Fortra GoAnywhere MFTCVE-2023-0669

    Fortra GoAnywhere MFT Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 7.2high

    Added Feb 10, 2023

  23. Rank 33

    SolarWinds Serv-UCVE-2021-35247

    SolarWinds Serv-U Improper Input Validation Vulnerability

    CVSS severity 5.3medium

    Added Jan 21, 2022

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.