Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.9% | — | Solarwinds Serv-u | 3/2/2021 | 17/6/2026 | SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. | |
| Modificada | Alta (7.5) | 1.5% | — | Solarwinds Serv-u | 7/7/2020 | 17/6/2026 | SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. | |
| Modificada | Media (6.1) | 1.5% | — | Solarwinds Serv-u | 7/7/2020 | 17/6/2026 | SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | |
| Modificada | Alta (7.5) | 1.5% | — | Solarwinds Serv-u | 7/7/2020 | 17/6/2026 | SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. | |
| Modificada | Media (6.1) | 1.5% | — | Solarwinds Serv-u | 7/7/2020 | 17/6/2026 | SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | |
| Modificada | Crítica (9.8) | 1.6% | — | Solarwinds Serv-u FTP Server | 5/7/2020 | 17/6/2026 | SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path. | |
| Modificada | Crítica (9.8) | 1.6% | — | Solarwinds Serv-u FTP Server | 5/7/2020 | 17/6/2026 | SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command. | |
| Modificada | Crítica (9.8) | 7.0% | — | Solarwinds Serv-u FTP Server | 5/7/2020 | 17/6/2026 | SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution. | |
| Modificada | Alta (8.8) | 0.77% | — | Solarwinds Serv-u Managed File Transfer | 18/3/2020 | 17/6/2026 | SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters. | |
| Modificada | Media (5.4) | 2.3% | — | Solarwinds Serv-u FTP Server | 18/12/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. | |
| Modificada | Media (5.4) | 6.4% | — | Solarwinds Serv-u FTP Server | 16/12/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. | |
| Modificada | Media (6.5) | 3.2% | — | Solarwinds Serv-u FTP Server | 16/12/2019 | 17/6/2026 | A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. | |
| Modificada | Alta (8.8) | 66% | 💥 Exploit | Solarwinds Serv-u FTP ServerSolarwinds Serv-u MFT Server | 17/6/2019 | 17/6/2026 | A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | |
| Modificada | Alta (7.8) | 0.60% | — | Solarwinds Serv-u FTP Server | 7/6/2019 | 17/6/2026 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have… | |
| Modificada | Media (4.8) | 5.4% | — | Solarwinds Serv-u FTP Server | 21/3/2019 | 17/6/2026 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter. | |
| Modificada | Alta (7.2) | 8.1% | — | Solarwinds Serv-u FTP Server | 21/3/2019 | 17/6/2026 | SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file. | |
| Modificada | Media (6.5) | 1.7% | — | Solarwinds Serv-u | 16/5/2018 | 17/6/2026 | A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring. | |
| Modificada | Alta (7.3) | 1.0% | — | Solarwinds Serv-u | 16/5/2018 | 17/6/2026 | SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the… | |
| Modificada | Alta (9) | 7.3% | 💥 Exploit | Solarwinds Serv-u File Server | 14/12/2011 | 16/6/2026 | Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directories, via a "..:/" (dot dot colon forward slash) in the (1) list, (2) put, or (3) get commands. | |
| Modificada | Alta (10) | 21% | 💥 Exploit | Rhinosoft Serv-u | 26/5/2010 | 16/6/2026 | Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie. | |
| Modificada | Media (4) | 2.9% | — | Solarwinds Serv-u File Server | 27/4/2010 | 16/6/2026 | Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (10) | 83% | 💥 Exploit | Solarwinds Serv-u File Server | 20/11/2009 | 16/6/2026 | Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. | |
| Modificada | Media (5) | 4.0% | — | Solarwinds Serv-u File Server | 9/10/2009 | 16/6/2026 | Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command. | |
| Modificada | Alta (7.8) | 11% | 💥 Exploit | Solarwinds Serv-u File Server | 20/3/2009 | 16/6/2026 | Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request. | |
| Modificada | Media (4) | 7.0% | 💥 Exploit | Solarwinds Serv-u File Server | 19/3/2009 | 16/6/2026 | The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument. |