Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 59% | 💥 Exploit | Openbsd FtpdWashington University Wu-ftpd | 7/7/2000 | 16/6/2026 | FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands. | |
| Modificada | Alta (10) | 4.2% | — | Glftpd | 26/6/2000 | 16/6/2026 | The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability. | |
| Modificada | Alta (10) | 8.0% | 💥 Exploit | H. Nomura Tiny Ftpdaemon | 1/2/2000 | 16/6/2026 | Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Jgaa Warftpd | 1/2/2000 | 16/6/2026 | Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands. | |
| Modificada | Alta (10) | 3.1% | — | Jgaa Warftpd | 6/1/2000 | 16/6/2026 | Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands. | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Glftpd | 23/12/1999 | 16/6/2026 | glFtpD includes a default glftpd user account with a default password and a UID of 0. | |
| Modificada | Alta (10) | 1.9% | — | Glftpd | 23/12/1999 | 16/6/2026 | glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command. | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Millenux Gmbh AnonftpUniversity OF Washington Wu-ftpdRedhat Linux | 20/12/1999 | 16/6/2026 | wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress. | |
| Modificada | Media (5) | 1.9% | — | Jgaa Warftpd | 13/12/1999 | 16/6/2026 | War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections. | |
| Modificada | Media (4.6) | 4.4% | — | Proftpd Project Proftpd | 19/11/1999 | 16/6/2026 | ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command. | |
| Modificada | Alta (10) | 8.1% | 💥 Exploit | Texas Imperial Software Wftpd | 28/10/1999 | 16/6/2026 | Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | |
| Modificada | Alta (10) | 38% | 💥 Exploit | Proftpd Project Proftpd | 27/8/1999 | 16/6/2026 | Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories. | |
| Modificada | Alta (10) | 2.2% | — | BeroftpdWashington University Wu-ftpd | 22/8/1999 | 16/6/2026 | Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR. | |
| Modificada | Alta (10) | 40% | 💥 Exploit | Proftpd Project ProftpdWashington University Wu-ftpdCaldera OpenlinuxDebian Linux+4 | 9/2/1999 | 16/6/2026 | Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto. | |
| Modificada | Alta (10) | 54% | 💥 Exploit | TCP WrappersAIWuftpdAIIrciiAISendmailAI+2 | 1/1/1999 | 16/6/2026 | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6. | |
| Modificada | Alta (7.5) | 2.3% | — | Ncftpd Server | 1/1/1999 | 16/6/2026 | Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | Jgaa WarftpdMicrosoft Windows 95Microsoft Windows NT | 1/2/1998 | 16/6/2026 | Buffer overflow in War FTP allows remote execution of commands. | |
| Modificada | Alta (7.5) | 2.0% | — | GNU InetWashington University Wu-ftpdCaldera OpenlinuxFreebsd+7 | 10/12/1997 | 16/6/2026 | FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. | |
| Modificada | Alta (7.6) | 2.5% | — | Washington University Wu-ftpd | 23/9/1997 | 16/6/2026 | Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command. | |
| Modificada | Media (5) | 1.5% | — | Washington University Wu-ftpd | 4/7/1997 | 16/6/2026 | wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files. | |
| Modificada | Media (5) | 1.7% | — | Washington University Wu-ftpd | 1/7/1997 | 16/6/2026 | Buffer overflow in wu-ftp from PASV command causes a core dump. | |
| Modificada | Media (4.6) | 0.40% | — | Washington University Wu-ftpd | 1/7/1997 | 16/6/2026 | wu-ftpd FTP daemon allows any user and password combination. | |
| Modificada | Media (5) | 1.6% | — | Washington University Wu-ftpd | 11/1/1997 | 16/6/2026 | wu-ftp allows files to be overwritten via the rnfr command. | |
| Modificada | Alta (7.5) | 2.0% | — | University OF Washington Wu-ftpd | 1/1/1997 | 16/6/2026 | The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands. | |
| Modificada | Media (5) | 1.6% | — | Washington University Wu-ftpd | 16/10/1996 | 16/6/2026 | PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password. |