Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.7%💥 ExploitEnterprisedt Completeftp Server2/10/201917/6/2026
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
ModificadaMedia (5.3)15%💥 ExploitCoreftp Core FTP22/3/201917/6/2026
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
ModificadaMedia (5.3)14%💥 ExploitCoreftp Core FTP22/3/201917/6/2026
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
ModificadaAlta (7.5)8.5%💥 ExploitCoreftp Core FTP2/1/201917/6/2026
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
ModificadaCrítica (9.8)6.9%—Coreftp Core FTP5/7/201817/6/2026
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
ModificadaAlta (7.8)0.36%—Coreftp Core FTP20/3/201817/6/2026
Multiple buffer overflows in Core FTP Server before 1.2 build 508 allow local users to gain privileges via vectors related to reading data from config.dat and Windows Registry.
ModificadaMedia (6.1)0.95%—Netwin Surgeftp29/12/201717/6/2026
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
ModificadaCrítica (9.8)1.5%—Pureftpd Pure-ftpdFedoraproject Fedora21/9/201717/6/2026
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue…
ModificadaMedia (5)8.8%💥 ExploitCoreftp Core FTP25/6/201417/6/2026
Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.
ModificadaMedia (4)1.8%—Coreftp Core FTP2/5/201417/6/2026
Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read.
ModificadaMedia (4)2.4%—Coreftp Core FTP2/5/201417/6/2026
Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command.
ModificadaMedia (4.3)1.9%—Coreftp Core FTP2/5/201417/6/2026
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.
ModificadaAlta (9.3)3.0%—Coreftp Core FTP4/4/201416/6/2026
Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply.
ModificadaAlta (7.5)4.3%—Netwin Surgeftp9/8/201316/6/2026
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
ModificadaMedia (5.1)2.3%—Coreftp29/3/201316/6/2026
Multiple buffer overflows in Core FTP before 2.2 build 1769 allow remote FTP servers to execute arbitrary code or cause a denial of service (application crash) via a long directory name in a (1) DELE, (2) LIST, or (3) VIEW command.
ModificadaAlta (10)3.1%—Freeftpd4/12/201216/6/2026
freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.
ModificadaAlta (9.3)29%💥 ExploitVandyke Absoluteftp15/9/201216/6/2026
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
ModificadaBaja (3.6)0.58%💥 ExploitPureftpd Pure-ftpd4/11/201116/6/2026
Directory traversal vulnerability in pure-FTPd 1.0.22 and possibly other versions, when running on SUSE Linux Enterprise Server and possibly other operating systems, when the Netware OES remote server feature is enabled, allows local users to overwrite arbitrary files via unknown vectors.
ModificadaMedia (4)7.3%💥 ExploitPureftpd Pure-ftpdNetbsd24/5/201116/6/2026
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions containing curly brackets, which allows remote authenticated users to cause a denial of service (memory consumption) via a crafted FTP STAT command.
ModificadaMedia (5.8)33%💥 PoCPureftpd Pure-ftpd23/5/201116/6/2026
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted FTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection"…
ModificadaMedia (4.4)0.34%—Pureftpd Pure-ftpdNovell Suse Linux18/4/201116/6/2026
pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.
ModificadaMedia (6.9)0.32%—Bareftp20/10/201016/6/2026
bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (4.3)1.1%—Netwin Surgeftp23/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in surgeftpmgr.cgi in NetWin SurgeFTP 2.3a6 allow remote attackers to inject arbitrary web script or HTML via the (1) domainid or (2) classid parameter in a class action.
ModificadaAlta (9.3)5.6%💥 ExploitCoreftp Core FTP30/9/200916/6/2026
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)4.7%—Globalscape Cuteftp30/9/200916/6/2026
Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and 8.3.3.0054 allows user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a site list containing an entry with a long label.
Orbitaley — Vulnerabilidades