Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)7.7%—Accellion FTP Server13/7/201817/6/2026
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
ModificadaCrítica (9.8)1.1%—THE Olive Tree FTP Server Project THE Olive Tree FTP Server15/6/201817/6/2026
The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User password" field with the Drozer post.capture.clipboard module.
ModificadaCrítica (9.8)1.5%—Theolivetree FTP Server29/5/201817/6/2026
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.
ModificadaAlta (7.5)7.5%💥 ExploitSegger Embos/ip FTP Server4/3/201817/6/2026
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR command.
ModificadaCrítica (9.8)14%💥 ExploitCerberus FTP Server17/3/201717/6/2026
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.
ModificadaAlta (7.5)15%—Efssoft Easy File Sharing FTP Server16/3/201717/6/2026
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.
ModificadaAlta (7.5)8.6%💥 ExploitCerberusftp FTP Server14/3/201717/6/2026
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
ModificadaAlta (7.8)58%💥 ExploitPcman FTP Server29/9/201519/8/2026
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.
ModificadaMedia (6.8)2.4%—Wftpserver Wing FTP Server10/6/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to…
ModificadaAlta (7.8)58%💥 ExploitIpswitch Tftp Server28/12/201416/6/2026
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.
ModificadaMedia (5)2.7%💥 ExploitHillstone Software HS Tftp Server28/12/201416/6/2026
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.
ModificadaAlta (10)14%💥 ExploitFreefloat FTP Server20/6/201416/6/2026
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.
ModificadaAlta (10)66%💥 ExploitPcman FTP Server15/5/201419/8/2026
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
ModificadaMedia (5)4.7%💥 ExploitSouthrivertech Titan FTP Server29/4/201417/6/2026
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a .. (dot dot) in the src parameter.
ModificadaMedia (5)5.3%💥 ExploitSouthrivertech Titan FTP Server29/4/201417/6/2026
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value.
ModificadaMedia (5)4.9%💥 ExploitSouthrivertech Titan FTP Server29/4/201417/6/2026
Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.
ModificadaMedia (4.3)1.2%—Cerberusftp FTP Server31/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and might allow (2) remote authenticated…
ModificadaMedia (6.8)2.2%—Wftpserver Wing FTP Server26/10/201216/6/2026
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
ModificadaMedia (4)8.5%💥 ExploitTypsoft FTP Server8/10/201216/6/2026
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application crash) via a long string in an APPE command.
ModificadaMedia (5)1.2%—Cerberusftp FTP Server4/10/201216/6/2026
The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.
ModificadaMedia (6.8)1.2%—Cerberusftp FTP Server4/10/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to…
ModificadaMedia (6.8)31%💥 ExploitRicoh Dl-10Ricoh Sr10 FTP Server19/9/201216/6/2026
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote attackers to execute arbitrary code via a long USER FTP command.
ModificadaMedia (4.3)4.9%💥 ExploitBlackmoonftpserver Blackmoon FTP Server20/1/201116/6/2026
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to cause a denial of service (crash) via a large number of PORT commands with long arguments, which triggers a NULL pointer dereference. NOTE: some of these details are…
ModificadaMedia (6.5)1.9%—Xlightftpd Xlight FTP Server12/7/201016/6/2026
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
ModificadaMedia (4)1.5%—Cerberusftp FTP Server2/7/201016/6/2026
Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.