Products › IT administration and security
IT administration and security
Managed file transfer (MFT)
Platforms for exchanging and sharing files with outside parties, often exposed to the internet.
For example: MOVEit, GoAnywhere, CrushFTP, Cleo.
-
7 vulnerabilities added in the last 12 months
-
33 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Citrix 2 vulnerabilities
- Cleo 2 vulnerabilities
- CrushFTP 3 vulnerabilities
- Fortra 2 vulnerabilities
- Gladinet 4 vulnerabilities · 3 in the last 12 months
- IBM 1 vulnerability
- Kiteworks (Accellion) 4 vulnerabilities
- North Grid 1 vulnerability
- ownCloud 2 vulnerabilities · 1 in the last 12 months
- Progress 2 vulnerabilities
- ProjectSend 1 vulnerability
- Rejetto 2 vulnerabilities
- SolarWinds 4 vulnerabilities · 1 in the last 12 months
- Soliton Systems 1 vulnerability · 1 in the last 12 months
- Wing FTP Server 2 vulnerabilities · 1 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Backup, storage and NAS 38 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
ownCloud ServerCVE-2023-49105
ownCloud Improper Authentication Vulnerability
Hunt for compromise (CISA)CVE from 2023, added in 2026
CVSS severity 9.8critical
Added Aug 27, 2026
- Rank 2
Gladinet CentreStack / TriofoxCVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
CVSS severity 9.8critical
Added Dec 15, 2025
- Rank 3
Gladinet CentreStack / TriofoxCVE-2025-12480
Gladinet Triofox Improper Access Control Vulnerability
CVSS severity 9.1critical
Added Nov 12, 2025
- Rank 4
Soliton Systems FileZenCVE-2026-25108
Soliton Systems K.K FileZen OS Command Injection Vulnerability
CVSS severity 8.8high
Added Feb 24, 2026
- Rank 5
SolarWinds Serv-UCVE-2026-28318
SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
CVSS severity 7.5high
Added Jun 5, 2026
- Rank 6
Gladinet CentreStack / TriofoxCVE-2025-11371
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
CVSS severity 7.5high
Added Nov 4, 2025
- Rank 7
Wing FTP ServerCVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability
CVSS severity 4.3medium
Added Mar 16, 2026
- Rank 8
Wing FTP ServerCVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
CVSS severity 10.0critical
Added Jul 14, 2025
- Rank 9
CrushFTPCVE-2024-4040
CrushFTP VFS Sandbox Escape Vulnerability
CVSS severity 10.0critical
Added Apr 24, 2024
- Rank 10
SolarWinds Serv-UCVE-2021-35211
SolarWinds Serv-U Remote Code Execution Vulnerability
Ransomware
CVSS severity 10.0critical
Added Nov 3, 2021
Show 23 more vulnerabilities
- Rank 11
Fortra GoAnywhere MFTCVE-2025-10035
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 9.8critical
Added Sep 29, 2025
- Rank 12
CrushFTPCVE-2025-54309
CrushFTP Unprotected Alternate Channel Vulnerability
CVSS severity 9.8critical
Added Jul 22, 2025
- Rank 13
Gladinet CentreStack / TriofoxCVE-2025-30406
Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
CVSS severity 9.8critical
Added Apr 8, 2025
- Rank 14
CrushFTPCVE-2025-31161
CrushFTP Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Apr 7, 2025
- Rank 15
Cleo Harmony / VLTrader / LexiComCVE-2024-55956
Cleo Multiple Products Unauthenticated File Upload Vulnerability
Ransomware
CVSS severity 9.8critical
Added Dec 17, 2024
- Rank 16
Cleo Harmony / VLTrader / LexiComCVE-2024-50623
Cleo Multiple Products Unrestricted File Upload Vulnerability
Ransomware
CVSS severity 9.8critical
Added Dec 13, 2024
- Rank 17
ProjectSendCVE-2024-11680
ProjectSend Improper Authentication Vulnerability
CVSS severity 9.8critical
Added Dec 3, 2024
- Rank 18
Rejetto HTTP File Server (HFS)CVE-2024-23692
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jul 9, 2024
- Rank 19
Citrix ShareFileCVE-2023-24489
Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
CVSS severity 9.8critical
Added Aug 16, 2023
- Rank 20
Progress MOVEit TransferCVE-2023-34362
Progress MOVEit Transfer SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jun 2, 2023
- Rank 21
IBM Aspera FaspexCVE-2022-47986
IBM Aspera Faspex Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Feb 21, 2023
- Rank 22
Rejetto HTTP File Server (HFS)CVE-2014-6287
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
CVE from 2014, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 23
Citrix ShareFileCVE-2021-22941
Citrix ShareFile Improper Access Control Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 24
Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27101
Accellion FTA SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 25
Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27103
Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 26
Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27104
Accellion FTA OS Command Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 27
Progress WS_FTP ServerCVE-2023-40044
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 8.8high
Added Oct 5, 2023
- Rank 28
Kiteworks (Accellion) FTA (File Transfer Appliance)CVE-2021-27102
Accellion FTA OS Command Injection Vulnerability
Ransomware
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 29
North Grid ProselfCVE-2023-45727
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
CVSS severity 7.5high
Added Dec 3, 2024
- Rank 30
SolarWinds Serv-UCVE-2024-28995
SolarWinds Serv-U Path Traversal Vulnerability
CVSS severity 7.5high
Added Jul 17, 2024
- Rank 31
ownCloud ServerCVE-2023-49103
ownCloud graphapi Information Disclosure Vulnerability
CVSS severity 7.5high
Added Nov 30, 2023
- Rank 32
Fortra GoAnywhere MFTCVE-2023-0669
Fortra GoAnywhere MFT Remote Code Execution Vulnerability
Ransomware
CVSS severity 7.2high
Added Feb 10, 2023
- Rank 33
SolarWinds Serv-UCVE-2021-35247
SolarWinds Serv-U Improper Input Validation Vulnerability
CVSS severity 5.3medium
Added Jan 21, 2022
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.