Filtered by vendor Accellion
Subscriptions
Filtered by product Kiteworks
Subscriptions
Total
4 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-53939 | 2 Accellion, Kiteworks | 2 Kiteworks, Kiteworks | 2025-12-04 | 6.3 Medium |
| Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0. | ||||
| CVE-2021-31586 | 1 Accellion | 1 Kiteworks | 2024-11-21 | 8.8 High |
| Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. | ||||
| CVE-2021-31585 | 1 Accellion | 1 Kiteworks | 2024-11-21 | 6.7 Medium |
| Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access. | ||||
| CVE-2017-9421 | 1 Accellion | 1 Kiteworks | 2024-11-21 | N/A |
| Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token. | ||||
Page 1 of 1.