Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)1.6%—Cooolsoft Personal FTP Server31/3/200316/6/2026
Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get.
ModificadaMedia (5)13%💥 ExploitSolarwinds Tftp Server31/3/200316/6/2026
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
ModificadaMedia (5)1.5%—Mollensoft Software Hyperion FTP Server31/12/200216/6/2026
Directory traversal vulnerability in Hyperion FTP server 2.8.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the LS command.
ModificadaMedia (5)1.8%—Tftp Server31/12/200216/6/2026
tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.
ModificadaMedia (5)1.5%—Kunani Odbc FTP Server31/12/200216/6/2026
Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.
ModificadaAlta (10)1.4%—Pablo Software Solutions Baby FTP Server31/12/200216/6/2026
Unspecified "security vulnerability" in Baby FTP Server versions before November 7, 2002 has unknown impact and attack vectors.
ModificadaMedia (5)1.3%—Typsoft FTP Server18/12/200216/6/2026
Directory traversal vulnerability in TYPSoft FTP Server 0.99.8 allows local users to list the contents of arbitrary directories via a ... (dot dot dot) in the cd/CWD command.
ModificadaAlta (7.5)3.0%—Pablo Software Solutions Pablo FTP Server12/11/200216/6/2026
Format string vulnerability in Pablo FTP Server 1.5, 1.3, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via format strings in the USER command.
ModificadaMedia (5)13%💥 ExploitSolarwinds Tftp Server4/11/200216/6/2026
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
ModificadaMedia (6.4)2.2%—Pablo Software Solutions Pablo FTP Server4/10/200216/6/2026
Directory traversal vulnerability in Pablo FTP server 1.0 build 9 and earlier allows remote authenticated users to list arbitrary directories via "..\" (dot-dot backslash) sequences in a LIST command.
ModificadaAlta (7.5)12%—Progress WS FTP Server12/8/200216/6/2026
Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.
ModificadaAlta (10)5.3%—Transsoft Broker FTP Server26/7/200216/6/2026
Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.
ModificadaMedia (5)2.1%—Typsoft FTP Server3/7/200216/6/2026
Directory traversal vulnerability in TYPSoft FTP server 0.97.1 and earlier allows a remote authenticated user (possibly anonymous) to list arbitrary directories via a .. in a LIST (ls) command ending in wildcard *.* characters.
ModificadaMedia (5)2.0%—Dynu Systems Inc. Dynu FTP Server25/6/200216/6/2026
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.
ModificadaAlta (7.5)4.2%—Selom Ofori Blackmoon FTP Server25/3/200216/6/2026
Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.
ModificadaAlta (7.5)1.3%—Grant Averett Ceberus FTP Server6/12/200116/6/2026
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.
ModificadaMedia (5)1.7%—Cisco Tftp Server18/10/200116/6/2026
Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command.
ModificadaMedia (4.6)0.44%—Bisonware Bison FTP Server18/10/200116/6/2026
BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories.
ModificadaMedia (5)1.8%—A-ftp Anonymous FTP Server18/10/200116/6/2026
Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command.
ModificadaMedia (5)7.1%💥 ExploitTypsoft FTP Server8/10/200116/6/2026
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.
ModificadaAlta (7.5)1.5%—Maxum Development Corporation Rumpus FTP Server20/9/200116/6/2026
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server.
ModificadaAlta (7.5)9.8%💥 ExploitGrant Averett Ceberus FTP Server20/9/200116/6/2026
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.
ModificadaMedia (5)3.2%💥 ExploitMaxum Development Corporation Rumpus FTP Server20/9/200116/6/2026
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length.
ModificadaMedia (5)1.7%—Transsoft Broker FTP Server20/9/200116/6/2026
Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).
ModificadaBaja (2.1)0.96%💥 ExploitMaxum Development Corporation Rumpus FTP Server20/9/200116/6/2026
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders.