Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 2.2% | 💥 Exploit | ProftpdAIProftpd MOD SQLAI | 29/11/2024 | 17/6/2026 | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql. | |
| Analizada | Alta (8.6) | 1.6% | 💥 Exploit | Pureftpd Pure-ftpd | 24/10/2024 | 17/6/2026 | pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. | |
| Modificada | Alta (7.3) | 0.26% | — | Raidenftpd | 13/2/2024 | 17/6/2026 | Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Xlightftpd Xlight FTP Server | 19/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.5) | 1.3% | — | Ftpdmin Project Ftpdmin | 7/1/2024 | 17/6/2026 | A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RNFR Command Handler. The manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Proftpd | 22/12/2023 | 17/6/2026 | make_ftp_cmd in main.c in ProFTPD before 1.3.8a has a one-byte out-of-bounds read, and daemon crash, because of mishandling of quote/backslash semantics. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.5) | 0.59% | — | Netbsd FtpdNetbsd Tnftpd | 5/10/2023 | 17/6/2026 | ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable. | |
| Modificada | Alta (7.8) | 0.45% | 💥 PoC | Raidenftpd | 11/9/2023 | 17/6/2026 | Buffer Overflow vulnerability in RaidenFTPD 2.4.4005 allows a local attacker to execute arbitrary code via the Server name field of the Step by step setup wizard. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Vsftpd Project Vsftpd | 22/8/2023 | 17/6/2026 | VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed. | |
| Modificada | Alta (7.5) | 0.86% | — | Wftpd Project Wftpd | 25/5/2023 | 17/6/2026 | In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006. | |
| Modificada | Alta (7.8) | 0.20% | — | Tftpd64 Project Tftpd64 | 17/2/2023 | 17/6/2026 | A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be… | |
| Modificada | Alta (7.5) | 1.2% | — | Proftpd | 23/11/2022 | 17/6/2026 | mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters. | |
| Modificada | Alta (7.5) | 2.0% | — | Glftpd | 7/7/2022 | 17/6/2026 | An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit. | |
| Modificada | Alta (8.1) | 2.2% | — | Xlightftpd Xlight FTP | 23/5/2022 | 17/6/2026 | Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code. | |
| Modificada | Alta (7.8) | 0.33% | — | Freesshd Freeftpd | 31/3/2022 | 17/6/2026 | FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | |
| Modificada | Alta (7.4) | 2.0% | — | F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+1 | 23/3/2022 | 17/6/2026 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to… | |
| Modificada | Alta (7.8) | 0.31% | — | Miniftpd Project Miniftpd | 4/11/2021 | 17/6/2026 | A local buffer overflow vulnerability exists in the latest version of Miniftpd in ftpproto.c through the tmp variable, where a crafted payload can be sent to the affected function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Miniftpd Project Miniftpd | 11/10/2021 | 17/6/2026 | A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Pureftpd Pure-ftpd | 5/9/2021 | 17/6/2026 | In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are… | |
| Modificada | Media (6.5) | 0.85% | — | Miniftpd Project Miniftpd | 23/8/2021 | 17/6/2026 | A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Crítica (9.8) | 3.5% | — | Ftpd Project Ftpd | 26/1/2021 | 16/6/2026 | The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Pureftpd Pure-ftpd | 26/12/2020 | 17/6/2026 | Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. | |
| Modificada | Crítica (9.8) | 26% | 💥 Exploit | Troglobit Uftpd | 18/12/2020 | 17/6/2026 | There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory,… | |
| Modificada | Crítica (9.8) | 3.4% | — | Troglobit Uftpd | 18/12/2020 | 17/6/2026 | An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution. |