Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

54 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)14%💥 ExploitIpswitch WS FTP HomeIpswitch WS FTP PRO20/8/200816/6/2026
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).
ModificadaMedia (5)5.6%—Ipswitch WS FTP6/2/200816/6/2026
The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different…
ModificadaAlta (9)22%💥 ExploitProgress WS FTP Server5/2/200816/6/2026
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.
ModificadaMedia (4.3)1.6%—Ipswitch WS FTP28/8/200716/6/2026
Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin…
ModificadaAlta (7.8)25%—Ipswitch WS FTP17/7/200716/6/2026
The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string to port 5151/udp.
ModificadaAlta (7.8)4.6%—Ipswitch WS FTP24/4/200716/6/2026
Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereference and application crash) via unspecified vectors related to "improper arguments."
ModificadaMedia (6.8)1.9%—Ipswitch WS FTP Server2/2/200716/6/2026
Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module.
ModificadaMedia (6.8)3.3%—Ipswitch WS FTP PRO2/2/200716/6/2026
Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command.
ModificadaAlta (7.5)3.4%—Ipswitch WS FTP PRO18/1/200716/6/2026
Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors.
ModificadaMedia (6.5)65%—Ipswitch WS FTP ServerProgress WS FTP Server26/9/200616/6/2026
Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong…
ModificadaMedia (5)32%—Ipswitch WS FTP ServerProgress WS FTP Server26/9/200616/6/2026
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for…
ModificadaAlta (7.5)4.2%💥 ExploitIpswitch WS FTP Server25/9/200616/6/2026
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.
ModificadaMedia (6.5)85%💥 ExploitIpswitch WS FTP ServerProgress WS FTP Server19/9/200616/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
ModificadaMedia (5)50%💥 ExploitIpswitch WS FTP Server10/1/200516/6/2026
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
ModificadaMedia (5)8.1%—Ipswitch WS FTP ServerProgress WS FTP Server31/12/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.
ModificadaAlta (7.2)5.2%💥 ExploitProgress WS FTP Server31/12/200416/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a…
ModificadaAlta (7.2)3.5%—Progress WS FTP Server31/12/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.
ModificadaMedia (5)7.5%💥 ExploitProgress WS FTP Server29/8/200416/6/2026
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.
ModificadaAlta (7.5)5.8%—Ipswitch WS FTP PROIpswitch WS FTP ServerProgress WS FTP Server23/3/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
ModificadaAlta (7.5)9.8%💥 ExploitHD Soft Windows FTP Server17/2/200416/6/2026
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
ModificadaAlta (7.5)85%💥 ExploitIpswitch WS FTP ServerProgress WS FTP Server22/9/200316/6/2026
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
ModificadaAlta (7.5)4.2%💥 ExploitBrowseftp Client31/12/200216/6/2026
Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.
ModificadaAlta (7.5)3.4%—Ipswitch WS FTP PRO31/12/200216/6/2026
Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.
ModificadaAlta (7.5)12%—Progress WS FTP Server12/8/200216/6/2026
Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.
ModificadaAlta (7.5)42%💥 ExploitProgress WS FTP Server26/7/200116/6/2026
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
Orbitaley — Vulnerabilidades