Products › IT administration and security
IT administration and security
Managed file transfer (MFT)
Platforms for exchanging and sharing files with outside parties, often exposed to the internet.
For example: MOVEit, GoAnywhere, CrushFTP, Cleo.
-
8 vulnerabilities added in the last 12 months
-
33 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Citrix 2 vulnerabilities
- Cleo 2 vulnerabilities
- CrushFTP 3 vulnerabilities
- Fortra 2 vulnerabilities · 1 in the last 12 months
- Gladinet 4 vulnerabilities · 3 in the last 12 months
- IBM 1 vulnerability
- Kiteworks (Accellion) 4 vulnerabilities
- North Grid 1 vulnerability
- ownCloud 2 vulnerabilities · 1 in the last 12 months
- Progress 2 vulnerabilities
- ProjectSend 1 vulnerability
- Rejetto 2 vulnerabilities
- SolarWinds 4 vulnerabilities · 1 in the last 12 months
- Soliton Systems 1 vulnerability · 1 in the last 12 months
- Wing FTP Server 2 vulnerabilities · 1 in the last 12 months
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Backup, storage and NAS 38 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1ownCloud Server
CVE-2023-49105Hunt for compromise (CISA)CVE from 2023, added in 2026
ownCloud Improper Authentication Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 27, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2Gladinet CentreStack / Triofox
CVE-2025-14611Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Dec 15, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 3Fortra GoAnywhere MFT
CVE-2025-10035Ransomware
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Sep 29, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 4Gladinet CentreStack / Triofox
CVE-2025-12480Gladinet Triofox Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 12, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 5Soliton Systems FileZen
CVE-2026-25108Soliton Systems K.K FileZen OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 24, 2026
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 6SolarWinds Serv-U
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 5, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 7Gladinet CentreStack / Triofox
CVE-2025-11371Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Nov 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 8Wing FTP Server
CVE-2025-47813Wing FTP Server Information Disclosure Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 16, 2026
- CISA deadline
- 14 days
- CVSS severity
- 4.3 (medium)
Rank 9Wing FTP Server
CVE-2025-47812Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 14, 2025
- CISA deadline
- 21 days
- CVSS severity
- 10.0 (critical)
Rank 10CrushFTP
CVE-2024-4040CrushFTP VFS Sandbox Escape Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 24, 2024
- CISA deadline
- 7 days
- CVSS severity
- 10.0 (critical)
Show 23 more vulnerabilities
Rank 11SolarWinds Serv-U
CVE-2021-35211Ransomware
SolarWinds Serv-U Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 10.0 (critical)
Rank 12CrushFTP
CVE-2025-54309CrushFTP Unprotected Alternate Channel Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Gladinet CentreStack / Triofox
CVE-2025-30406Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 8, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14CrushFTP
CVE-2025-31161Ransomware
CrushFTP Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 7, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 15Cleo Harmony / VLTrader / LexiCom
CVE-2024-55956Ransomware
Cleo Multiple Products Unauthenticated File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 16Cleo Harmony / VLTrader / LexiCom
CVE-2024-50623Ransomware
Cleo Multiple Products Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 13, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 17ProjectSend
CVE-2024-11680ProjectSend Improper Authentication Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 3, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 18Rejetto HTTP File Server (HFS)
CVE-2024-23692Ransomware
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 19Citrix ShareFile
CVE-2023-24489Citrix Content Collaboration ShareFile Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Progress MOVEit Transfer
CVE-2023-34362Ransomware
Progress MOVEit Transfer SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 2, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21IBM Aspera Faspex
CVE-2022-47986Ransomware
IBM Aspera Faspex Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 21, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Rejetto HTTP File Server (HFS)
CVE-2014-6287CVE from 2014, added in 2022
Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23Citrix ShareFile
CVE-2021-22941Ransomware
Citrix ShareFile Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Kiteworks (Accellion) FTA (File Transfer Appliance)
CVE-2021-27101Ransomware
Accellion FTA SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 25Kiteworks (Accellion) FTA (File Transfer Appliance)
CVE-2021-27103Ransomware
Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 26Kiteworks (Accellion) FTA (File Transfer Appliance)
CVE-2021-27104Ransomware
Accellion FTA OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 27Progress WS_FTP Server
CVE-2023-40044Ransomware
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 5, 2023
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 28Kiteworks (Accellion) FTA (File Transfer Appliance)
CVE-2021-27102Ransomware
Accellion FTA OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Rank 29North Grid Proself
CVE-2023-45727North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 3, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 30SolarWinds Serv-U
CVE-2024-28995SolarWinds Serv-U Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 17, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 31ownCloud Server
CVE-2023-49103ownCloud graphapi Information Disclosure Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 30, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 32Fortra GoAnywhere MFT
CVE-2023-0669Ransomware
Fortra GoAnywhere MFT Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 10, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 33SolarWinds Serv-U
CVE-2021-35247SolarWinds Serv-U Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 21, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.3 (medium)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.