Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 1.3% | — | Nightlight Fireftp | 29/9/2009 | 16/6/2026 | Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victims to alter permissions, delete, download, or move the wrong file via a filename containing "… | |
| Modificada | Alta (9.3) | 2.5% | 💥 Exploit | Visicommedia Aceftp | 19/11/2008 | 16/6/2026 | Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. | |
| Modificada | Alta (9.3) | 2.6% | — | Globalscape Cuteftp | 19/6/2008 | 16/6/2026 | Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be… | |
| Modificada | Alta (9.3) | 3.5% | — | Fireftp | 22/5/2008 | 16/6/2026 | Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code… | |
| Modificada | Media (6.4) | 6.8% | 💥 Exploit | Netwin Surgeftp | 27/2/2008 | 16/6/2026 | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails. | |
| Modificada | Alta (8.5) | 1.6% | — | Netwin Surgeftp | 15/7/2007 | 16/6/2026 | The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command. | |
| Modificada | Media (5.8) | 1.2% | — | Netwin Surgeftp | 15/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be… | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | FreeftpdFreesshdWeonlydo Wodsshserver | 16/5/2006 | 16/6/2026 | Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Helmsman Research Homeftp | 22/1/2006 | 16/6/2026 | Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Freeftpd | 26/11/2005 | 16/6/2026 | freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Freeftpd | 19/11/2005 | 16/6/2026 | Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Freeftpd | 19/11/2005 | 16/6/2026 | Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands. | |
| Modificada | Media (5) | 1.8% | — | Netwin Surgeftp | 2/5/2005 | 16/6/2026 | SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command. | |
| Modificada | Alta (7.2) | 0.87% | 💥 Exploit | Light Speed Technology Deluxeftp | 2/5/2005 | 16/6/2026 | Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.1% | — | Globalscape Cuteftp | 10/1/2005 | 16/6/2026 | Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands. | |
| Modificada | Media (5) | 1.9% | — | Surgeftp ServerAI | 31/12/2004 | 16/6/2026 | The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Pureftpd | 6/8/2004 | 16/6/2026 | The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections. | |
| Modificada | Alta (7.5) | 3.9% | — | Globalscape CuteftpAI | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner. | |
| Modificada | Baja (2.1) | 0.48% | — | Globalscape Cuteftp | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard. | |
| Modificada | Alta (7.6) | 8.7% | 💥 Exploit | Globalscape Cuteftp | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Browseftp Client | 31/12/2002 | 16/6/2026 | Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply. | |
| Modificada | Media (5) | 2.3% | — | Khamil Landross AND Zack Jones Eftp | 13/12/2001 | 16/6/2026 | Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Netwin Surgeftp | 20/9/2001 | 16/6/2026 | NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command. | |
| Modificada | Media (5) | 2.7% | — | Netwin Surgeftp | 20/9/2001 | 16/6/2026 | NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con. | |
| Modificada | Media (5) | 2.3% | — | Netwin Surgeftp | 20/9/2001 | 16/6/2026 | Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command. |