Vulnerabilities (CVE)

Filtered by vendor Fortra Subscribe
Total 27 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-25154 1 Fortra 1 Filecatalyst Direct 2026-06-17 N/A 5.3 MEDIUM
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.  
CVE-2024-25153 1 Fortra 1 Filecatalyst Workflow 2026-06-17 N/A 9.8 CRITICAL
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
CVE-2024-11922 1 Fortra 1 Goanywhere Managed File Transfer 2026-06-17 N/A 6.3 MEDIUM
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
CVE-2024-0259 2 Fortra, Microsoft 2 Robot Schedule, Windows 2026-06-17 N/A 7.3 HIGH
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When the service is restarted, the replaced binary runs with local system privileges, allowing a low-privileged user to gain elevated privileges.
CVE-2024-0204 1 Fortra 1 Goanywhere Managed File Transfer 2026-06-17 N/A 9.8 CRITICAL
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
CVE-2023-6253 1 Fortra 1 Digital Guardian Agent 2026-06-17 N/A 6.0 MEDIUM
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
CVE-2021-26837 1 Fortra 1 Delivernow 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.