Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Enterprisedt Completeftp Server | 2/10/2019 | 17/6/2026 | EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash. | |
| Modificada | Media (5.3) | 15% | 💥 Exploit | Coreftp Core FTP | 22/3/2019 | 17/6/2026 | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date. | |
| Modificada | Media (5.3) | 14% | 💥 Exploit | Coreftp Core FTP | 22/3/2019 | 17/6/2026 | An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information. | |
| Modificada | Alta (7.5) | 8.5% | 💥 Exploit | Coreftp Core FTP | 2/1/2019 | 17/6/2026 | The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command. | |
| Modificada | Crítica (9.8) | 6.9% | — | Coreftp Core FTP | 5/7/2018 | 17/6/2026 | Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response. | |
| Modificada | Alta (7.8) | 0.36% | — | Coreftp Core FTP | 20/3/2018 | 17/6/2026 | Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from config.dat and Windows Registry. | |
| Modificada | Media (6.1) | 0.95% | — | Netwin Surgeftp | 29/12/2017 | 17/6/2026 | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Pureftpd Pure-ftpdFedoraproject Fedora | 21/9/2017 | 17/6/2026 | Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Coreftp Core FTP | 25/6/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command. | |
| Modificada | Media (4) | 1.8% | — | Coreftp Core FTP | 2/5/2014 | 17/6/2026 | Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read. | |
| Modificada | Media (4) | 2.4% | — | Coreftp Core FTP | 2/5/2014 | 17/6/2026 | Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command. | |
| Modificada | Media (4.3) | 1.9% | — | Coreftp Core FTP | 2/5/2014 | 17/6/2026 | Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice. | |
| Modificada | Alta (9.3) | 3.0% | — | Coreftp Core FTP | 4/4/2014 | 16/6/2026 | Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply. | |
| Modificada | Alta (7.5) | 4.3% | — | Netwin Surgeftp | 9/8/2013 | 16/6/2026 | Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request. | |
| Modificada | Media (5.1) | 2.3% | — | Coreftp | 29/3/2013 | 16/6/2026 | Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command. | |
| Modificada | Alta (10) | 3.1% | — | Freeftpd | 4/12/2012 | 16/6/2026 | freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c. | |
| Modificada | Alta (9.3) | 29% | 💥 Exploit | Vandyke Absoluteftp | 15/9/2012 | 16/6/2026 | Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response. | |
| Modificada | Baja (3.6) | 0.58% | 💥 Exploit | Pureftpd Pure-ftpd | 4/11/2011 | 16/6/2026 | Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors. | |
| Modificada | Media (4) | 7.3% | 💥 Exploit | Pureftpd Pure-ftpdNetbsd | 24/5/2011 | 16/6/2026 | The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command. | |
| Modificada | Media (5.8) | 33% | 💥 PoC | Pureftpd Pure-ftpd | 23/5/2011 | 16/6/2026 | The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection"… | |
| Modificada | Media (4.4) | 0.34% | — | Pureftpd Pure-ftpdNovell Suse Linux | 18/4/2011 | 16/6/2026 | pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors. | |
| Modificada | Media (6.9) | 0.32% | — | Bareftp | 20/10/2010 | 16/6/2026 | bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (4.3) | 1.1% | — | Netwin Surgeftp | 23/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Coreftp Core FTP | 30/9/2009 | 16/6/2026 | Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 4.7% | — | Globalscape Cuteftp | 30/9/2009 | 16/6/2026 | Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a site list containing an entry with a long label. |