Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)1.4%—Southrivertech Titan MFT ServerSouthrivertech Titan Sftp Server16/10/202317/6/2026
Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
ModificadaAlta (7.5)3.2%💥 ExploitVsftpd Project Vsftpd22/8/202317/6/2026
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
ModificadaCrítica (9.8)0.57%—Greenend Sftpserver18/12/202217/6/2026
A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is…
ModificadaMedia (6.1)0.62%—Sftpgo Project Sftpgo20/9/202217/6/2026
SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilities in the SFTPGo WebClient, allowing remote attackers to inject malicious code. This issue is patched in version 2.3.5. No known workarounds exist.
ModificadaAlta (8.1)0.54%—Sftpgo Project Sftpgo2/9/202217/6/2026
SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support login using TOTP (Time-based One Time Passwords) as a secondary authentication factor. Because TOTPs are often configured on mobile devices that can be lost, stolen or damaged, SFTPGo also supports…
ModificadaAlta (7.4)2.0%—F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+123/3/202217/6/2026
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to…
ModificadaMedia (6.1)1.8%💥 ExploitCerberusftp FTP Server10/6/202117/6/2026
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
ModificadaAlta (8.1)1.2%—Cerberusftp FTP Server14/1/202017/6/2026
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing…
ModificadaMedia (5.4)0.68%—Cerberusftp FTP Server14/1/202017/6/2026
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip…
ModificadaMedia (6.1)1.2%—Cerberusftp FTP Server13/1/202017/6/2026
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path…
ModificadaCrítica (9.8)96%💥 ExploitVsftpd Project VsftpdDebian Linux27/11/201916/6/2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
ModificadaCrítica (9.1)1.4%—Solarwinds Sftp/scp Server5/12/201817/6/2026
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
ModificadaCrítica (9.8)1.5%—Solarwinds Sftp/scp Server5/12/201817/6/2026
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.
ModificadaMedia (5.3)0.56%—Psftpd15/11/201717/6/2026
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.
ModificadaMedia (5.9)8.7%💥 ExploitPsftpd15/11/201717/6/2026
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did not automatically restart, which enabled attackers to perform a very effective DoS attack against this service. By sending a crafted SSH…
ModificadaMedia (5.3)7.0%💥 ExploitPsftpd15/11/201717/6/2026
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. Special characters such as '"' and ',' and '\r' are not…
ModificadaMedia (4.3)1.5%—Psftpd15/11/201717/6/2026
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server.
ModificadaAlta (7.5)8.6%💥 ExploitCerberusftp FTP Server14/3/201717/6/2026
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
ModificadaMedia (5)6.8%💥 ExploitOpensuseVsftpd Project Vsftpd28/1/201517/6/2026
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
ModificadaMedia (4)1.1%—FAL Sftp Project FAL Sftp27/10/201417/6/2026
The fal_sftp extension before 0.2.6 for TYPO3 uses weak permissions for sFTP driver files and folders, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaMedia (4.3)1.2%—Cerberusftp FTP Server31/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cerberus FTP Server before 5.0.6.0 allow (1) remote attackers to inject arbitrary web script or HTML via a log entry that is not properly handled within the Log Manager component, and might allow (2) remote authenticated…
ModificadaMedia (5)1.2%—Cerberusftp FTP Server4/10/201216/6/2026
The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.
ModificadaMedia (6.8)1.2%—Cerberusftp FTP Server4/10/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in Cerberus FTP Server before 5.0.5.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user account or (2) reconfigure the state of the FTP service, as demonstrated by a request to…
ModificadaMedia (4)74%💥 ExploitVsftpd Project VsftpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+22/3/201116/6/2026
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
ModificadaAlta (9.3)1.4%—Crossftp PRO3/11/201016/6/2026
Directory traversal vulnerability in CrossFTP Pro 1.65a, and probably earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
Orbitaley — Vulnerabilidades