Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Wftpserver Wing FTP Server | 24/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request. | |
| Modificada | Media (5) | 2.7% | — | Filecopa-ftpserver FTP Server | 11/10/2009 | 16/6/2026 | FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands. | |
| Modificada | Alta (9) | 5.3% | — | Wftpserver Winftp FTP Server | 29/1/2009 | 16/6/2026 | Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character. | |
| Modificada | Baja (3.5) | 21% | — | Wftpserver Winftp FTP Server | 19/12/2008 | 16/6/2026 | WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command. | |
| Modificada | Media (6.8) | 2.7% | — | Conti Ftpserver | 29/6/2007 | 16/6/2026 | Conti FtpServer 1.0 allows remote authenticated users to cause a denial of service (daemon crash) via a certain string containing "//A:" in the argument to the LIST command. | |
| Modificada | Media (5) | 1.7% | — | Conti Ftpserver | 23/1/2007 | 16/6/2026 | Directory traversal vulnerability in Conti FTPServer 1.0 Build 2.8 allows remote attackers to read arbitrary files and list arbitrary directories via a .. (dot dot) in a filename argument. | |
| Modificada | Media (4.6) | 0.32% | — | Conti Ftpserver | 23/1/2007 | 16/6/2026 | Conti FTPServer 1.0 Build 2.8 stores user passwords in cleartext in MyServerSettings.ini, which allows local users to obtain sensitive information by reading this file. | |
| Modificada | Alta (7.5) | 67% | — | Goldenftpserver Golden FTP Server | 15/12/2006 | 16/6/2026 | Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634. | |
| Modificada | Media (5) | 3.1% | — | Platinumftpserver | 2/5/2005 | 16/6/2026 | PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username. | |
| Modificada | Alta (10) | 4.5% | — | Netscape Professional Services Ftpserver | 21/6/2000 | 16/6/2026 | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |