Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.5% | — | Cerberusftp FTP Server | 2/7/2010 | 16/6/2026 | Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands. | |
| Modificada | Alta (7.5) | 1.7% | — | Provider4u Vsftpd Webmin Module | 30/12/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues." | |
| Modificada | Alta (7.1) | 3.7% | — | Redhat Vsftpd | 9/7/2008 | 16/6/2026 | Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than… | |
| Modificada | Media (4) | 2.3% | — | Weonlydo Sftp | 31/5/2006 | 16/6/2026 | The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page. | |
| Modificada | Alta (7.5) | 1.9% | — | Phpsftpd | 19/7/2005 | 16/6/2026 | inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the password in the response. | |
| Modificada | Media (5) | 2.1% | — | Beasts Vsftpd | 31/12/2004 | 16/6/2026 | vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Samhain Labs Hsftp | 15/3/2004 | 16/6/2026 | Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command. | |
| Modificada | Media (5) | 1.2% | — | Beasts Vsftpd | 3/2/2004 | 16/6/2026 | vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames. |