Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.3%—Texas Imperial Software Wftpd20/9/200116/6/2026
WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).
ModificadaAlta (7.5)1.6%—Texas Imperial Software Wftpd20/9/200116/6/2026
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
ModificadaMedia (5)7.1%💥 ExploitGlftpd31/8/200116/6/2026
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
ModificadaMedia (5)1.4%—Whitsoft Development Slimftpd21/8/200116/6/2026
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.
ModificadaAlta (10)4.3%—Trolltech Trollftpd13/8/200116/6/2026
Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.
ModificadaAlta (7.5)3.0%—Texasimperialsoftware Wftpd1/7/200116/6/2026
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.
ModificadaMedia (5)5.7%💥 ExploitTeam Johnlong Raidenftpd27/6/200116/6/2026
Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.
ModificadaAlta (7.5)11%—Proftpd Project Proftpd2/6/200116/6/2026
Format string vulnerability in ProFTPD 1.2.0rc2 may allow attackers to execute arbitrary commands by shutting down the FTP server while using a malformed working directory (cwd).
ModificadaAlta (10)5.0%💥 ExploitTexas Imperial Software Wftpd PRO3/5/200116/6/2026
Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.
ModificadaMedia (5)8.1%💥 ExploitJarle Aase WAR Ftpd3/5/200116/6/2026
Directory traversal vulnerability in War FTP 1.67.04 allows remote attackers to list directory contents and possibly read files via a "dir *./../.." command.
ModificadaAlta (10)5.7%💥 ExploitWashington University Wu-ftpd26/3/200116/6/2026
Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.
ModificadaMedia (5)45%💥 ExploitProftpdConectiva LinuxDebian LinuxMandrakesoft Mandrake Linux12/3/200116/6/2026
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
ModificadaAlta (7.5)6.5%—Proftpd Project Proftpd12/2/200116/6/2026
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.
ModificadaAlta (10)4.8%—Max-wilhelm Bruker Bftpd12/2/200116/6/2026
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.
ModificadaAlta (10)18%💥 ExploitDavid Madore Ftpd-bsdNetbsdOpenbsd12/2/200116/6/2026
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
ModificadaMedia (5)1.9%—Texas Imperial Software Wftpd9/1/200116/6/2026
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
ModificadaAlta (7.5)3.8%—Max-wilhelm Bruker Bftpd19/12/200023/9/2026
Buffer overflow in bftp daemon (bftpd) 1.0.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER command.
ModificadaMedia (5)1.5%—Texas Imperial Software WftpdTexas Imperial Software Wftpd PRO14/11/200016/6/2026
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to obtain the full pathname of the server via a "%C" command, which generates an error message that includes the pathname.
ModificadaMedia (5)1.7%—Texas Imperial Software WftpdTexas Imperial Software Wftpd PRO14/11/200016/6/2026
WFTPD and WFTPD Pro 2.41 RC12 allows remote attackers to cause a denial of service by sending a long string of unprintable characters.
ModificadaMedia (5)2.2%—Texas Imperial Software Wftpd21/7/200016/6/2026
WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.
ModificadaMedia (5)7.3%💥 ExploitTexas Imperial Software Wftpd21/7/200016/6/2026
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing.
ModificadaMedia (6.4)4.9%💥 ExploitTexas Imperial Software Wftpd21/7/200016/6/2026
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).
ModificadaMedia (5)5.3%💥 ExploitTexas Imperial Software Wftpd21/7/200016/6/2026
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.
ModificadaMedia (5)3.7%💥 ExploitTexas Imperial Software Wftpd11/7/200016/6/2026
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.
ModificadaAlta (7.5)7.2%💥 ExploitSteve Poulsen Guildftpd8/7/200016/6/2026
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not.
Orbitaley — Vulnerabilidades