Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 5.1% | — | Winagents Tftp Server | 24/4/2006 | 16/6/2026 | Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request. | |
| Modificada | Alta (7.8) | 3.3% | — | Futuresoft Tftp Server 2000 | 1/6/2005 | 16/6/2026 | Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences. | |
| Modificada | Alta (10) | 63% | — | Futuresoft Tftp Server 2000 | 1/6/2005 | 16/6/2026 | Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet. | |
| Modificada | Media (5) | 2.5% | — | Winagents Tftp ServerAI | 31/12/2004 | 16/6/2026 | WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow. | |
| Modificada | Alta (10) | 8.1% | — | Robotftp Server | 23/11/2004 | 16/6/2026 | Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username. | |
| Modificada | Media (5) | 13% | — | Solarwinds Tftp Server | 31/3/2003 | 16/6/2026 | SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 1.8% | — | Tftp Server | 31/12/2002 | 16/6/2026 | tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux. | |
| Modificada | Media (5) | 13% | — | Solarwinds Tftp Server | 4/11/2002 | 16/6/2026 | Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request. | |
| Modificada | Media (5) | 1.7% | — | Cisco Tftp Server | 18/10/2001 | 16/6/2026 | Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. | |
| Modificada | Alta (7.5) | 4.2% | — | IBM Alphaworks Tftp Server | 20/7/2001 | 16/6/2026 | Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack. |