Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.7%—Argosoft FTP Server31/12/200416/6/2026
Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via ".." sequences in the SITE UNZIP argument.
ModificadaBaja (2.1)3.0%💥 ExploitTypsoft FTP Server31/12/200416/6/2026
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty".
ModificadaAlta (7.5)1.3%—Argosoft FTP Server31/12/200416/6/2026
ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack.
ModificadaMedia (5)36%💥 ExploitBolintech Dream FTP Server31/12/200416/6/2026
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.
ModificadaMedia (5)2.8%—Argosoft FTP Server31/12/200416/6/2026
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
ModificadaAlta (7.2)3.5%—Progress WS FTP Server31/12/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.
ModificadaMedia (5)5.1%💥 ExploitKarjasoft Sami FTP Server31/12/200416/6/2026
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file.
ModificadaMedia (4)1.5%—Nexgen FTP ServerAI31/12/200416/6/2026
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.
ModificadaMedia (6.5)5.4%💥 ExploitOpenftpd FTP Server31/12/200416/6/2026
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.
ModificadaAlta (9)4.8%—Argosoft FTP Server31/12/200416/6/2026
Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument.
ModificadaMedia (4)3.0%💥 ExploitNexgen FTP ServerAI31/12/200416/6/2026
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands.
ModificadaBaja (2.1)0.34%—Winftp Server31/12/200416/6/2026
WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local users to gain access to the credentials.
ModificadaMedia (5)1.9%—Surgeftp ServerAI31/12/200416/6/2026
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
ModificadaMedia (6.8)3.4%💥 ExploitArgosoft FTP Server31/12/200416/6/2026
ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted.
ModificadaAlta (7.5)2.8%💥 ExploitNet2soft Flash FTP ServerAI31/12/200416/6/2026
Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot).
ModificadaAlta (7.2)5.2%💥 ExploitProgress WS FTP Server31/12/200416/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a…
ModificadaMedia (5)2.5%—Winagents Tftp ServerAI31/12/200416/6/2026
WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.
ModificadaAlta (7.5)1.4%—Argosoft FTP Server31/12/200416/6/2026
Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors.
ModificadaMedia (4)1.2%—Pablo Software Solutions Quick N Easy FTP Server31/12/200416/6/2026
Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists…
ModificadaMedia (5)3.8%💥 ExploitGlobalscape Secure FTP Server31/12/200416/6/2026
Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument.
ModificadaMedia (5)3.1%💥 ExploitTranssoft Broker FTP Server23/11/200416/6/2026
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection.
ModificadaAlta (10)14%💥 ExploitBolintech Dream FTP Server23/11/200416/6/2026
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.
ModificadaMedia (5)7.4%💥 ExploitXlight FTP Server23/11/200416/6/2026
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.
ModificadaMedia (5)1.7%—Transsoft Broker FTP Server23/11/200416/6/2026
TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection.
ModificadaAlta (10)8.1%💥 ExploitRobotftp Server23/11/200416/6/2026
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.