Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Typsoft FTP Server23/11/200416/6/2026
TYPSoft FTP Server 1.10 allows remote attackers to cause a denial of service (CPU consumption) via an empty USER name.
ModificadaMedia (5)3.1%💥 ExploitCrob FTP Server23/11/200416/6/2026
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.
ModificadaMedia (5)7.3%💥 ExploitXlight FTP Server23/11/200416/6/2026
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a long argument containing a large number of / (slash) characters, possibly triggering a buffer overflow.
ModificadaMedia (5)7.5%💥 ExploitProgress WS FTP Server29/8/200416/6/2026
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.
ModificadaMedia (5)8.2%💥 ExploitSouth River Technologies Titan FTP Server29/8/200416/6/2026
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.
ModificadaMedia (5)7.7%💥 ExploitSouth River Technologies Titan FTP Server7/7/200416/6/2026
Titan FTP Server version 3.01 build 163, and possibly other versions before build 169, allows remote authenticated users to cause a denial of service (crash) by disconnecting from the system during a "LIST -L" command, which causes Titan to access an invalid socket.
ModificadaMedia (5)4.0%💥 ExploitOrenosv Http FTP Server26/5/200416/6/2026
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
ModificadaAlta (7.5)6.9%💥 ExploitMollensoft Software Lightweight FTP Server24/3/200416/6/2026
Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long CWD command, as demonstrated in one example by using the "cd" command in an interactive FTP client.
ModificadaAlta (7.5)5.8%—Ipswitch WS FTP PROIpswitch WS FTP ServerProgress WS FTP Server23/3/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
ModificadaAlta (7.5)9.8%💥 ExploitHD Soft Windows FTP Server17/2/200416/6/2026
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
ModificadaMedia (5)7.0%💥 ExploitKarjasoft Sami FTP Server13/2/200416/6/2026
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.
ModificadaMedia (5)1.8%—Matrix FTP ServerAI6/2/200416/6/2026
Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.
ModificadaMedia (5)3.0%💥 ExploitCrob FTP Server1/2/200416/6/2026
Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.
ModificadaBaja (2.1)0.29%—Cerberus FTP Server31/12/200316/6/2026
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.
ModificadaMedia (4.3)1.2%—Bisonftp Server 431/12/200316/6/2026
BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command.
ModificadaMedia (5)1.7%—Pablo Software Solutions Baby FTP Server31/12/200316/6/2026
Baby FTP Server (BabyFTP) 1.2, and possibly other versions before May 31, 2003, allows remote attackers to cause a denial of service via a large number of connections from the same IP address, which triggers an access violation.
ModificadaAlta (7.5)1.6%—Bisonftp Server 431/12/200316/6/2026
Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command.
ModificadaMedia (4)1.4%—Pablo Software Solutions Baby FTP Server31/12/200316/6/2026
Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.
ModificadaAlta (7.5)85%💥 ExploitIpswitch WS FTP ServerProgress WS FTP Server22/9/200316/6/2026
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
ModificadaMedia (5)1.6%—Crob FTP Server6/8/200316/6/2026
Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.
ModificadaMedia (5)1.7%—Crob FTP Server3/6/200316/6/2026
Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.
ModificadaAlta (7.5)3.9%—Cooolsoft Personal FTP Server27/5/200316/6/2026
Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument.
ModificadaMedia (4.6)0.48%—Selom Ofori Blackmoon FTP Server21/5/200316/6/2026
BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks.
ModificadaMedia (4.6)0.31%—Selom Ofori Blackmoon FTP Server20/5/200316/6/2026
BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges.
ModificadaMedia (5)1.3%—Cooolsoft Personal FTP Server31/3/200316/6/2026
CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response.