Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)2.2%💥 ExploitProftpdAIProftpd MOD SQLAI29/11/202417/6/2026
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
AnalizadaAlta (8.6)1.6%💥 ExploitPureftpd Pure-ftpd24/10/202417/6/2026
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
ModificadaAlta (7.3)0.26%—Raidenftpd13/2/202417/6/2026
Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.
ModificadaAlta (7.5)4.2%💥 ExploitXlightftpd Xlight FTP Server19/1/202417/6/2026
A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (7.5)1.3%—Ftpdmin Project Ftpdmin7/1/202417/6/2026
A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RNFR Command Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may…
ModificadaAlta (7.5)4.2%💥 ExploitProftpd22/12/202317/6/2026
make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaAlta (7.5)0.59%—Netbsd FtpdNetbsd Tnftpd5/10/202317/6/2026
ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.
ModificadaAlta (7.8)0.45%💥 PoCRaidenftpd11/9/202317/6/2026
Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard.
ModificadaAlta (7.5)3.2%💥 ExploitVsftpd Project Vsftpd22/8/202317/6/2026
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
ModificadaAlta (7.5)0.86%—Wftpd Project Wftpd25/5/202317/6/2026
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.
ModificadaAlta (7.8)0.20%—Tftpd64 Project Tftpd6417/2/202317/6/2026
A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be…
ModificadaAlta (7.5)1.2%—Proftpd23/11/202217/6/2026
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
ModificadaAlta (7.5)2.0%—Glftpd7/7/202217/6/2026
An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.
ModificadaAlta (8.1)2.2%—Xlightftpd Xlight FTP23/5/202217/6/2026
Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.
ModificadaAlta (7.8)0.33%—Freesshd Freeftpd31/3/202217/6/2026
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
ModificadaAlta (7.4)2.0%—F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+123/3/202217/6/2026
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to…
ModificadaAlta (7.8)0.31%—Miniftpd Project Miniftpd4/11/202117/6/2026
A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, where a crafted payload can be sent to the affected function.
ModificadaCrítica (9.8)1.4%—Miniftpd Project Miniftpd11/10/202117/6/2026
A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
ModificadaAlta (7.5)4.3%💥 ExploitPureftpd Pure-ftpd5/9/202117/6/2026
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are…
ModificadaMedia (6.5)0.85%—Miniftpd Project Miniftpd23/8/202117/6/2026
A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a remote malicious user cause a Denial of Service.
ModificadaCrítica (9.8)3.5%—Ftpd Project Ftpd26/1/202116/6/2026
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.
ModificadaAlta (7.5)4.5%💥 ExploitPureftpd Pure-ftpd26/12/202017/6/2026
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
ModificadaCrítica (9.8)26%💥 ExploitTroglobit Uftpd18/12/202017/6/2026
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory,…
ModificadaCrítica (9.8)3.4%—Troglobit Uftpd18/12/202017/6/2026
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.
Orbitaley — Vulnerabilidades