Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)85%—Ipswitch WS FTP ServerProgress WS FTP Server19/9/200616/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
ModificadaMedia (5)50%—Ipswitch WS FTP Server10/1/200516/6/2026
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
ModificadaAlta (7.2)3.5%—Progress WS FTP Server31/12/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.
ModificadaMedia (5)8.1%—Ipswitch WS FTP ServerProgress WS FTP Server31/12/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file.
ModificadaAlta (7.2)5.2%—Progress WS FTP Server31/12/200416/6/2026
Multiple buffer overflows in Ipswitch WS_FTP Server 4.0.2 (1) allow remote authenticated users to execute arbitrary code by causing a large error string to be generated by the ALLO handler, or (2) may allow remote FTP administrators to execute arbitrary code by causing a long hostname or username to be inserted into a…
ModificadaMedia (5)7.5%—Progress WS FTP Server29/8/200416/6/2026
WS_FTP 5.0.2 allows remote authenticated users to cause a denial of service (CPU consumption) via a CD command that contains an invalid path with a "../" sequence.
ModificadaAlta (7.5)5.8%—Ipswitch WS FTP PROIpswitch WS FTP ServerProgress WS FTP Server23/3/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
ModificadaAlta (7.5)9.8%—HD Soft Windows FTP Server17/2/200416/6/2026
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
ModificadaAlta (7.5)85%—Ipswitch WS FTP ServerProgress WS FTP Server22/9/200316/6/2026
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
ModificadaAlta (7.5)12%—Progress WS FTP Server12/8/200216/6/2026
Buffer overflow in WS_FTP FTP Server 3.1.1 allows remote authenticated users to execute arbitrary code via a long SITE CPWD command.
ModificadaAlta (7.5)42%—Progress WS FTP Server26/7/200116/6/2026
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
ModificadaMedia (5)2.1%—Ipswitch WS FTP Server2/2/199916/6/2026
WS_FTP server remote denial of service through cwd command.
ModificadaMedia (4.6)4.9%—Ipswitch ImailProgress WS FTP Server2/2/199916/6/2026
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.
ModificadaMedia (4.6)3.7%—Ipswitch ImailProgress WS FTP Server2/1/199916/6/2026
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.