Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.7% | — | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to determine the existence of arbitrary files via ".." sequences in the SITE UNZIP argument. | |
| Modificada | Baja (2.1) | 3.0% | 💥 Exploit | Typsoft FTP Server | 31/12/2004 | 16/6/2026 | TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (CPU consumption) via "//../" arguments to (1) mkd, (2) xmkd, (3) dele, (4) size, (5) retr, (6) stor, (7) appe, (8) rnfr, (9) rnto, (10) rmd, or (11) xrmd, as demonstrated using "//../qwerty". | |
| Modificada | Alta (7.5) | 1.3% | — | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | ArGoSoft FTP 1.4.2.4 and earlier does not limit the number of times that a bad password can be entered, which makes it easier for remote attackers to guess passwords via a brute force attack. | |
| Modificada | Media (5) | 36% | 💥 Exploit | Bolintech Dream FTP Server | 31/12/2004 | 16/6/2026 | Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands. | |
| Modificada | Media (5) | 2.8% | — | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames. | |
| Modificada | Alta (7.2) | 3.5% | — | Progress WS FTP Server | 31/12/2004 | 16/6/2026 | Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe. | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | Karjasoft Sami FTP Server | 31/12/2004 | 16/6/2026 | The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by issuing (1) a CD command with a tilde (~) character or dot dot (/../) or (2) a GET command for an unavailable file. | |
| Modificada | Media (4) | 1.5% | — | Nexgen FTP ServerAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands. | |
| Modificada | Media (6.5) | 5.4% | 💥 Exploit | Openftpd FTP Server | 31/12/2004 | 16/6/2026 | Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument. | |
| Modificada | Alta (9) | 4.8% | — | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in ArGoSoft FTP Server before 1.4.1.6 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a SITE ZIP command with a long first or second argument, or (2) a SITE COPY with a long argument. | |
| Modificada | Media (4) | 3.0% | 💥 Exploit | Nexgen FTP ServerAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls), (d) RNFR, or (e) RNTO FTP commands. | |
| Modificada | Baja (2.1) | 0.34% | — | Winftp Server | 31/12/2004 | 16/6/2026 | WinFTP Server 1.6 stores username and password credentials in plaintext in the data\user.wfd file, which allows local users to gain access to the credentials. | |
| Modificada | Media (5) | 1.9% | — | Surgeftp ServerAI | 31/12/2004 | 16/6/2026 | The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | ArGoSoft FTP Server before 1.4.1.6 allows remote authenticated users to cause a denial of service (crash) via a SITE PASS command with a long password parameter, which causes the database to be corrupted. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Net2soft Flash FTP ServerAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary files via a /.. (slash dot dot). | |
| Modificada | Alta (7.2) | 5.2% | 💥 Exploit | Progress WS FTP Server | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a… | |
| Modificada | Media (5) | 2.5% | — | Winagents Tftp ServerAI | 31/12/2004 | 16/6/2026 | WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow. | |
| Modificada | Alta (7.5) | 1.4% | — | Argosoft FTP Server | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in ArGoSoft FTP server before 1.4.2.2 allows attackers to upload .lnk files via unknown vectors. | |
| Modificada | Media (4) | 1.2% | — | Pablo Software Solutions Quick N Easy FTP Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists… | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Globalscape Secure FTP Server | 31/12/2004 | 16/6/2026 | Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Transsoft Broker FTP Server | 23/11/2004 | 16/6/2026 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a denial of service (CPU consumption) via an open idle connection. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Bolintech Dream FTP Server | 23/11/2004 | 16/6/2026 | Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Xlight FTP Server | 23/11/2004 | 16/6/2026 | Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 1.7% | — | Transsoft Broker FTP Server | 23/11/2004 | 16/6/2026 | TsFtpSrv.exe in Broker FTP 6.1.0.0 allows remote attackers to cause a TsFtpSrv.exe to exit with an exception by opening and immediately closing a connection. | |
| Modificada | Alta (10) | 8.1% | 💥 Exploit | Robotftp Server | 23/11/2004 | 16/6/2026 | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username. |