Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9)22%💥 ExploitProgress WS FTP Server5/2/200816/6/2026
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.
ModificadaMedia (4.3)1.2%—Cerberus FTP Server10/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (10)3.6%💥 ExploitProsysinfo Tftp Server Tftpdwin13/5/200716/6/2026
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.
ModificadaAlta (10)13%💥 ExploitFuturesoft Tftp Server 200024/3/200716/6/2026
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812.
ModificadaAlta (10)43%💥 ExploitD-link Tftp Server13/3/200716/6/2026
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.3)68%💥 ExploitProsysinfo Tftp Server Tftpdwin10/3/200716/6/2026
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.
ModificadaAlta (7.5)5.0%💥 ExploitDxmsoft XM Easy Personal FTP Server2/3/200716/6/2026
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.
ModificadaMedia (6.8)1.9%—Ipswitch WS FTP Server2/2/200716/6/2026
Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module.
ModificadaMedia (4.6)0.40%—Maxum Development Corporation Rumpus FTP Server19/1/200716/6/2026
Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files.
ModificadaMedia (4.6)0.40%—Maxum Development Corporation Rumpus FTP Server19/1/200716/6/2026
Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program.
ModificadaMedia (6.5)3.8%💥 ExploitMaxum Development Corporation Rumpus FTP Server19/1/200716/6/2026
Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service.
ModificadaAlta (7.5)4.7%💥 ExploitBolintech Dreamftp Server18/1/200716/6/2026
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.
ModificadaMedia (5)3.4%💥 ExploitDxmsoft XM Easy Personal FTP Server27/12/200616/6/2026
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands. NOTE: It was later reported that 5.3.0 is also vulnerable.
ModificadaMedia (5)2.2%💥 ExploitDxmsoft XM Easy Personal FTP Server27/12/200616/6/2026
Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long PORT command. NOTE: this issue might be related to CVE-2006-2226.
ModificadaMedia (4)2.5%💥 ExploitBolintech Dream FTP Server26/12/200616/6/2026
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of service (application crash) via a certain invalid PORT command.
ModificadaMedia (5)3.0%💥 ExploitWinftp Server21/12/200616/6/2026
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER, (4) PORT, and possibly other commands.
ModificadaMedia (5)2.9%💥 ExploitFightersoft Multimedia Star FTP Server20/12/200616/6/2026
Fightersoft Multimedia Star FTP server 1.10 allows remote attackers to cause a denial of service (crash) via multiple RETR commands with long arguments.
ModificadaAlta (7.5)67%💥 ExploitGoldenftpserver Golden FTP Server15/12/200616/6/2026
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.
ModificadaMedia (5)6.4%💥 ExploitCrob FTP Server14/12/200616/6/2026
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2) NLST command.
ModificadaMedia (4)1.3%—Telnet FTP Server3/12/200616/6/2026
Directory traversal vulnerability in Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to list contents of arbitrary directories and download arbitrary files via a .. (dot dot) sequence in an FTP command argument, as demonstrated by RETR (GET) or STOR (PUT). NOTE: The provenance of this information…
ModificadaMedia (4)1.2%—Telnet FTP Server3/12/200616/6/2026
Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to cause a denial of service (crash) via consecutive RETR commands. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.4)1.6%—Biba Software Seleniumserver FTP Server20/11/200616/6/2026
Multiple directory traversal vulnerabilities in SeleniumServer FTP Server 1.0, and possibly earlier, allow remote attackers to list arbitrary directories, read arbitrary files, and upload arbitrary files via directory traversal sequences in the (1) DIR (LIST or NLST), (2) GET (RETR), and (3) PUT (STOR) commands.
ModificadaAlta (10)2.7%—Biba Software Seleniumserver FTP Server20/11/200616/6/2026
SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to obtain passwords by reading the file. NOTE: the provenance of this information is unknown; details are obtained from third party sources.
ModificadaMedia (5)1.6%—Conxint FTP Server17/11/200616/6/2026
Multiple directory traversal vulnerabilities in Conxint FTP Server 2.2.0603, and possibly earlier, allow remote attackers to read arbitrary files and list arbitrary directories via directory traversal sequences in (1) DIR (LIST or NLST) and (2) GET (RETR) commands. NOTE: the provenance of this information is unknown;…
ModificadaMedia (5)1.7%—Altools Alftp FTP Server17/11/200616/6/2026
Directory traversal vulnerability in ALTools ALFTP FTP Server 4.1 beta 1, and possibly earlier, allows remote attackers to create arbitrary directories via directory traversal sequences in a MKD request. NOTE: the provenance of this information is unknown; details are obtained from third party sources.