Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)59%💥 ExploitOpenbsd FtpdWashington University Wu-ftpd7/7/200016/6/2026
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
ModificadaAlta (10)4.2%—Glftpd26/6/200016/6/2026
The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completion capability.
ModificadaAlta (10)8.0%💥 ExploitH. Nomura Tiny Ftpdaemon1/2/200016/6/2026
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.
ModificadaMedia (5)7.6%💥 ExploitJgaa Warftpd1/2/200016/6/2026
Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.
ModificadaAlta (10)3.1%—Jgaa Warftpd6/1/200016/6/2026
Macros in War FTP 1.70 and 1.67b2 allow local or remote attackers to read arbitrary files or execute commands.
ModificadaAlta (7.5)6.6%💥 ExploitGlftpd23/12/199916/6/2026
glFtpD includes a default glftpd user account with a default password and a UID of 0.
ModificadaAlta (10)1.9%—Glftpd23/12/199916/6/2026
glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.
ModificadaAlta (7.5)6.2%💥 ExploitMillenux Gmbh AnonftpUniversity OF Washington Wu-ftpdRedhat Linux20/12/199916/6/2026
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
ModificadaMedia (5)1.9%—Jgaa Warftpd13/12/199916/6/2026
War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.
ModificadaMedia (4.6)4.4%—Proftpd Project Proftpd19/11/199916/6/2026
ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.
ModificadaAlta (10)8.1%💥 ExploitTexas Imperial Software Wftpd28/10/199916/6/2026
Buffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
ModificadaAlta (10)38%💥 ExploitProftpd Project Proftpd27/8/199916/6/2026
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.
ModificadaAlta (10)2.2%—BeroftpdWashington University Wu-ftpd22/8/199916/6/2026
Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.
ModificadaAlta (10)40%💥 ExploitProftpd Project ProftpdWashington University Wu-ftpdCaldera OpenlinuxDebian Linux+49/2/199916/6/2026
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
ModificadaAlta (10)54%💥 ExploitTCP WrappersAIWuftpdAIIrciiAISendmailAI+21/1/199916/6/2026
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6.
ModificadaAlta (7.5)2.3%—Ncftpd Server1/1/199916/6/2026
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
ModificadaAlta (7.5)73%💥 ExploitJgaa WarftpdMicrosoft Windows 95Microsoft Windows NT1/2/199816/6/2026
Buffer overflow in War FTP allows remote execution of commands.
ModificadaAlta (7.5)2.0%—GNU InetWashington University Wu-ftpdCaldera OpenlinuxFreebsd+710/12/199716/6/2026
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
ModificadaAlta (7.6)2.5%—Washington University Wu-ftpd23/9/199716/6/2026
Race condition in wu-ftpd and BSDI ftpd allows remote attackers to gain root access via the SITE EXEC command.
ModificadaMedia (5)1.5%—Washington University Wu-ftpd4/7/199716/6/2026
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
ModificadaMedia (5)1.7%—Washington University Wu-ftpd1/7/199716/6/2026
Buffer overflow in wu-ftp from PASV command causes a core dump.
ModificadaMedia (4.6)0.40%—Washington University Wu-ftpd1/7/199716/6/2026
wu-ftpd FTP daemon allows any user and password combination.
ModificadaMedia (5)1.6%—Washington University Wu-ftpd11/1/199716/6/2026
wu-ftp allows files to be overwritten via the rnfr command.
ModificadaAlta (7.5)2.0%—University OF Washington Wu-ftpd1/1/199716/6/2026
The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.
ModificadaMedia (5)1.6%—Washington University Wu-ftpd16/10/199616/6/2026
PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.