Rejetto's vulnerability footprint centers on its HTTP File Server, a lightweight file-sharing application with a narrow product scope but notable reach in deployment. The recurring exposure involves template-engine injection, OS command injection, buffer overflows, and access-control weaknesses characteristic of web-facing server software handling user input and system-level operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rejetto over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23692CRITICAL Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to exe | May 31, 2024 | 9.8 | 99 | YES | YES |
CVE-2014-6287CRITICAL The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a % | Oct 7, 2014 | 9.8 | 99 | YES | YES |
CVE-2024-39943HIGH rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occu | Jul 4, 2024 | 8.8 | 55 | NO | NO |
CVE-2020-13432HIGH rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concur | Jun 8, 2020 | 7.5 | 33 | NO | NO |
CVE-2014-7226HIGH The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte se | Oct 10, 2014 | 7.5 | 32 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rejetto.
Media articles that mention a CVE ID that affects a product developed by Rejetto — matched by CVE ID, not by vendor name.