Vulnerabilities > GFI > High

DATE CVE VULNERABILITY TITLE RISK
2025-04-28 CVE-2025-34491 Deserialization of Untrusted Data vulnerability in GFI Mailessentials
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue.
network
low complexity
gfi CWE-502
8.8
2025-04-28 CVE-2025-34489 Deserialization of Untrusted Data vulnerability in GFI Mailessentials
GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue.
local
low complexity
gfi CWE-502
7.8
2024-12-12 CVE-2024-11947 Deserialization of Untrusted Data vulnerability in GFI Archiver
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability.
network
low complexity
gfi CWE-502
8.8
2024-12-12 CVE-2024-11949 Deserialization of Untrusted Data vulnerability in GFI Archiver
GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability.
network
low complexity
gfi CWE-502
8.8
2023-03-15 CVE-2023-25267 Out-of-bounds Write vulnerability in GFI Kerio Connect 9.4.1
An issue was discovered in GFI Kerio Connect 9.4.1 patch 1 (fixed in 10.0.0).
network
low complexity
gfi CWE-787
8.8