Products: 5
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-9177

    Server-Side Template Injection in SecureTransport's Apache Velocity mail templates

    Last Modified: Jul 29, 2026
    Published: Jul 29, 2026

    CVE-2019-14277

    Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.

    Last Modified: Nov 21, 2024
    Published: Jul 26, 2019

    CVE-2015-5606

    Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a specially crafted request.

    Last Modified: Nov 21, 2024
    Published: Apr 03, 2019

    CVE-2019-6500

    In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.

    Last Modified: Nov 21, 2024
    Published: Jan 21, 2019

    CVE-2013-7057

    Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.

    Last Modified: Apr 12, 2025
    Published: Nov 04, 2014
    Items Per Page
    Axway Vulnerabilities & Security CVEs | CVE-DB