Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)1.3%—Nightlight Fireftp29/9/200916/6/2026
Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victims to alter permissions, delete, download, or move the wrong file via a filename containing "…
ModificadaAlta (9.3)2.5%💥 ExploitVisicommedia Aceftp19/11/200816/6/2026
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.
ModificadaAlta (9.3)2.6%—Globalscape Cuteftp19/6/200816/6/2026
Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be…
ModificadaAlta (9.3)3.5%—Fireftp22/5/200816/6/2026
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code…
ModificadaMedia (6.4)6.8%💥 ExploitNetwin Surgeftp27/2/200816/6/2026
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.
ModificadaAlta (8.5)1.6%—Netwin Surgeftp15/7/200716/6/2026
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed response to a PASV command.
ModificadaMedia (5.8)1.2%—Netwin Surgeftp15/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be…
ModificadaAlta (7.5)71%💥 ExploitFreeftpdFreesshdWeonlydo Wodsshserver16/5/200616/6/2026
Stack-based buffer overflow in (1) WeOnlyDo wodSSHServer ActiveX Component 1.2.7 and 1.3.3 DEMO, as used in other products including (2) FreeSSHd 1.0.9 and (3) freeFTPd 1.0.10, allows remote attackers to execute arbitrary code via a long key exchange algorithm string.
ModificadaMedia (5)3.1%💥 ExploitHelmsman Research Homeftp22/1/200616/6/2026
Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.
ModificadaMedia (6.8)3.0%💥 ExploitFreeftpd26/11/200516/6/2026
freeFTPd 1.0.10 allows remote authenticated users to cause a denial of service (null dereference and crash) via a PORT command with missing arguments.
ModificadaAlta (7.5)72%💥 ExploitFreeftpd19/11/200516/6/2026
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a long USER command.
ModificadaAlta (7.5)14%💥 ExploitFreeftpd19/11/200516/6/2026
Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via long (1) MKD and (2) DELE commands.
ModificadaMedia (5)1.8%—Netwin Surgeftp2/5/200516/6/2026
SurgeFTP 2.2m1 allows remote attackers to cause a denial of service (application hang) via the LEAK command.
ModificadaAlta (7.2)0.87%💥 ExploitLight Speed Technology Deluxeftp2/5/200516/6/2026
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
ModificadaMedia (5)1.1%—Globalscape Cuteftp10/1/200516/6/2026
Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.
ModificadaMedia (5)1.9%—Surgeftp ServerAI31/12/200416/6/2026
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
ModificadaMedia (5)2.3%💥 ExploitPureftpd6/8/200416/6/2026
The accept_client function in PureFTPd 1.0.18 and earlier allows remote attackers to cause a denial of service by exceeding the maximum number of connections.
ModificadaAlta (7.5)3.9%—Globalscape CuteftpAI31/12/200316/6/2026
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
ModificadaBaja (2.1)0.48%—Globalscape Cuteftp31/12/200316/6/2026
Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
ModificadaAlta (7.6)8.7%💥 ExploitGlobalscape Cuteftp31/12/200316/6/2026
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
ModificadaAlta (7.5)4.2%💥 ExploitBrowseftp Client31/12/200216/6/2026
Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.
ModificadaMedia (5)2.3%—Khamil Landross AND Zack Jones Eftp13/12/200116/6/2026
Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command.
ModificadaMedia (5)7.1%💥 ExploitNetwin Surgeftp20/9/200116/6/2026
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
ModificadaMedia (5)2.7%—Netwin Surgeftp20/9/200116/6/2026
NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to cause a denial of service (crash) via a CD command to a directory with an MS-DOS device name such as con.
ModificadaMedia (5)2.3%—Netwin Surgeftp20/9/200116/6/2026
Directory traversal vulnerability in NetWin SurgeFTP 2.0a and 1.0b allows a remote attacker to list arbitrary files and directories via the 'nlist ...' command.
Orbitaley — Vulnerabilidades