Записи GFI
50 опубликованных записей вендора gfi.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 12 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')25
- CWE-502 Deserialization of Untrusted Data6
- CWE-306 Missing Authentication for Critical Function3
- CWE-203 Observable Discrepancy2
- CWE-862 Missing Authorization2
- CWE-611 Improper Restriction of XML External Entity Reference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
50 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2024-52875Proof of concept | An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.gfi · kerio control · CWE-113 | Высокая8,8 | — | 29,3 % | 31 янв. 2025 г. |
41В плане | CVE-2004-1312Эксплойта нет | A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause agfi · mailessentials | Критическая10,0 | — | 2,5 % | 3 янв. 2005 г. |
40В плане | CVE-2021-29281Эксплойта нет | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which gfi · archiver · CWE-434 | Критическая9,8 | — | 2,6 % | 7 июл. 2022 г. |
40В плане | CVE-2025-34070Эксплойта нет | GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfacesgfi · kerio control · CWE-306 | Критическая10,0 | — | 0,8 % | 2 июл. 2025 г. |
39Наблюдать | CVE-2024-11948Эксплойта нет | GFI Archiver Telerik Web UI Remote Code Execution Vulnerabilitygfi · archiver · CWE-1395 | Критическая9,8 | — | 1,4 % | 11 дек. 2024 г. |
39Наблюдать | CVE-2026-2039Эксплойта нет | GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerabilitygfi · archiver · CWE-862 | Критическая9,8 | — | 0,7 % | 20 февр. 2026 г. |
39Наблюдать | CVE-2026-2038Эксплойта нет | GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerabilitygfi · archiver · CWE-862 | Критическая9,8 | — | 0,7 % | 20 февр. 2026 г. |
38Наблюдать | CVE-2025-34069Proof of concept | GFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwardinggfi · kerio control · CWE-306 | Критическая9,5 | — | 0,7 % | 2 июл. 2025 г. |
37Наблюдать | CVE-2025-34071Эксплойта нет | GFI Kerio Control Unsigned System Image Upload Root Code Executiongfi · kerio control · CWE-306 | Критическая9,4 | — | 0,8 % | 2 июл. 2025 г. |
35Наблюдать | CVE-2026-2036Эксплойта нет | GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerabilitygfi · archiver · CWE-502 | Высокая8,8 | — | 1,2 % | 20 февр. 2026 г. |
35Наблюдать | CVE-2026-2037Эксплойта нет | GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerabilitygfi · archiver · CWE-502 | Высокая8,8 | — | 1,2 % | 20 февр. 2026 г. |
35Наблюдать | CVE-2023-25267Эксплойта нет | An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0).gfi · kerio connect · CWE-787 | Высокая8,8 | — | 1,0 % | 15 мар. 2023 г. |
35Наблюдать | CVE-2025-34491Эксплойта нет | GFI MailEssentials < 21.8 MultiNode Insecure Deserializationgfi · mailessentials · CWE-502 | Высокая8,8 | — | 0,9 % | 28 апр. 2025 г. |
35Наблюдать | CVE-2024-11949Эксплойта нет | GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerabilitygfi · archiver · CWE-502 | Высокая8,8 | — | 0,8 % | 11 дек. 2024 г. |
35Наблюдать | CVE-2024-11947Эксплойта нет | GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerabilitygfi · archiver · CWE-502 | Высокая8,8 | — | 0,8 % | 11 дек. 2024 г. |
32Наблюдать | CVE-2002-1121Эксплойта нет | SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3gfi · mailsecurity | Высокая7,5 | — | 6,7 % | 24 сент. 2002 г. |
31Наблюдать | CVE-2005-3182Эксплойта нет | Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headersgfi · mailsecurity | Высокая7,5 | — | 4,0 % | 20 окт. 2005 г. |
31Наблюдать | CVE-2025-34489Эксплойта нет | GFI MailEssentials < 21.8 Local Privilege Escalationgfi · mailessentials · CWE-502 | Высокая7,8 | — | 0,3 % | 28 апр. 2025 г. |
28Наблюдать | CVE-2010-5181Эксплойта нет | Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerogfi · vipre antivirus · CWE-362 | Высокая7,0 | — | 0,3 % | 25 авг. 2012 г. |
27Наблюдать | CVE-2010-5254Эксплойта нет | Untrusted search path vulnerability in GFI Backup 3.1 Build 20100730 2009 Home Edition allows local users to gain privileges via a Trojan hogfi · gfi backup 2009 | Средняя6,9 | — | 0,4 % | 7 сент. 2012 г. |
26Наблюдать | CVE-2017-7440Эксплойта нет | Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail previewgfi · kerio connect · CWE-1021 | Средняя6,5 | — | 0,9 % | 2 мая 2017 г. |
26Наблюдать | CVE-2025-34490Эксплойта нет | GFI MailEssentials < 21.8 XXE Arbitrary File Readgfi · mailessentials · CWE-611 | Средняя6,5 | — | 0,7 % | 28 апр. 2025 г. |
25Наблюдать | CVE-2026-23758Эксплойта нет | GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parametergfi · helpdesk · CWE-79 | Средняя6,4 | — | 0,2 % | 20 апр. 2026 г. |
24Наблюдать | CVE-2019-16414Эксплойта нет | A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's cleargfi · kerio control · CWE-79 | Средняя6,1 | — | 1,6 % | 30 сент. 2019 г. |
21Наблюдать | CVE-2026-23621Эксплойта нет | GFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to File Enumerationgfi · mailessentials · CWE-203 | Средняя5,3 | — | 0,3 % | 19 февр. 2026 г. |
- CVE-2024-5287544В плане
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5.
ВысокаяCVSS 8,8Proof of conceptEPSS 29 %gfi · kerio control31 янв. 2025 г.
- CVE-2004-131241В плане
A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %gfi · mailessentials3 янв. 2005 г.
- CVE-2021-2928140В плане
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gfi · archiver7 июл. 2022 г.
- CVE-2025-3407040В плане
GFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %gfi · kerio control2 июл. 2025 г.
- CVE-2024-1194839Наблюдать
GFI Archiver Telerik Web UI Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gfi · archiver11 дек. 2024 г.
- CVE-2026-203939Наблюдать
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gfi · archiver20 февр. 2026 г.
- CVE-2026-203839Наблюдать
GFI Archiver MArc.Core Missing Authorization Authentication Bypass Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %gfi · archiver20 февр. 2026 г.
- CVE-2025-3406938Наблюдать
GFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwarding
КритическаяCVSS 9,5Proof of conceptEPSS 1 %gfi · kerio control2 июл. 2025 г.
- CVE-2025-3407137Наблюдать
GFI Kerio Control Unsigned System Image Upload Root Code Execution
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %gfi · kerio control2 июл. 2025 г.
- CVE-2026-203635Наблюдать
GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · archiver20 февр. 2026 г.
- CVE-2026-203735Наблюдать
GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · archiver20 февр. 2026 г.
- CVE-2023-2526735Наблюдать
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · kerio connect15 мар. 2023 г.
- CVE-2025-3449135Наблюдать
GFI MailEssentials < 21.8 MultiNode Insecure Deserialization
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · mailessentials28 апр. 2025 г.
- CVE-2024-1194935Наблюдать
GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · archiver11 дек. 2024 г.
- CVE-2024-1194735Наблюдать
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gfi · archiver11 дек. 2024 г.
- CVE-2002-112132Наблюдать
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %gfi · mailsecurity24 сент. 2002 г.
- CVE-2005-318231Наблюдать
Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %gfi · mailsecurity20 окт. 2005 г.
- CVE-2025-3448931Наблюдать
GFI MailEssentials < 21.8 Local Privilege Escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gfi · mailessentials28 апр. 2025 г.
- CVE-2010-518128Наблюдать
Race condition in VIPRE Antivirus Premium 4.0.3272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangero
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %gfi · vipre antivirus25 авг. 2012 г.
- CVE-2010-525427Наблюдать
Untrusted search path vulnerability in GFI Backup 3.1 Build 20100730 2009 Home Edition allows local users to gain privileges via a Trojan ho
СредняяCVSS 6,9Эксплойта нетEPSS 0 %gfi · gfi backup 20097 сент. 2012 г.
- CVE-2017-744026Наблюдать
Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gfi · kerio connect2 мая 2017 г.
- CVE-2025-3449026Наблюдать
GFI MailEssentials < 21.8 XXE Arbitrary File Read
СредняяCVSS 6,5Эксплойта нетEPSS 1 %gfi · mailessentials28 апр. 2025 г.
- CVE-2026-2375825Наблюдать
GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter
СредняяCVSS 6,4Эксплойта нетEPSS 0 %gfi · helpdesk20 апр. 2026 г.
- CVE-2019-1641424Наблюдать
A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send back a victim's clear
СредняяCVSS 6,1Эксплойта нетEPSS 2 %gfi · kerio control30 сент. 2019 г.
- CVE-2026-2362121Наблюдать
GFI MailEssentials AI < 22.4 ListServer.IsPathExist() Absolute Directory Traversal to File Enumeration
СредняяCVSS 5,3Эксплойта нетEPSS 0 %gfi · mailessentials19 февр. 2026 г.