Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Xlightftpd Xlight FTP Server | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command. | |
| Modificada | Media (5) | 5.0% | 💥 Exploit | Cisco Tftp Server | 29/3/2010 | 16/6/2026 | Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 0.74% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames." | |
| Modificada | Media (5) | 1.8% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Solarwinds Tftp Server | 9/9/2009 | 16/6/2026 | SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 55% | 💥 Exploit | Netmechanica Netdecision Tftp Server | 20/5/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Wonko Notftp | 24/4/2009 | 16/6/2026 | Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter. | |
| Modificada | Media (5) | 2.2% | — | Windows Tftp Utility Tftputil | 27/1/2009 | 16/6/2026 | k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request. | |
| Modificada | Media (5) | 2.7% | — | Windows Tftp Utility Tftputil | 27/1/2009 | 16/6/2026 | Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request. | |
| Modificada | Alta (10) | 65% | 💥 Exploit | Tftp Server SP | 12/5/2008 | 16/6/2026 | Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Tallsoft Quick Tftp Server PRO | 1/4/2008 | 16/6/2026 | Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request. | |
| Modificada | Alta (10) | 68% | 💥 Exploit | Tftp-server Winagents Tftp Server | 1/4/2008 | 16/6/2026 | Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request. | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Bootmanage AdministratorBootmanage Tftpd | 20/3/2008 | 16/6/2026 | Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename. | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 13/5/2007 | 16/6/2026 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Futuresoft Tftp Server 2000 | 24/3/2007 | 16/6/2026 | Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812. | |
| Modificada | Alta (10) | 43% | 💥 Exploit | D-link Tftp Server | 13/3/2007 | 16/6/2026 | Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.3) | 68% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 10/3/2007 | 16/6/2026 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Smartftp | 6/2/2007 | 16/6/2026 | Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner. | |
| Modificada | Alta (10) | 70% | 💥 Exploit | 3com 3ctftpsvc | 1/12/2006 | 16/6/2026 | Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command. | |
| Modificada | Alta (10) | 66% | 💥 Exploit | Alliedtelesyn At-tftp | 1/12/2006 | 16/6/2026 | Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command. | |
| Modificada | Media (5) | 3.8% | — | Philippe Jounin Tftpd32 | 28/11/2006 | 16/6/2026 | Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 23/9/2006 | 16/6/2026 | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 5.7% | 💥 Exploit | Futuresoft Tftp Server Multithreaded | 14/9/2006 | 16/6/2026 | Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained… | |
| Modificada | Media (5) | 4.0% | — | Solarwinds Tftp Server | 24/4/2006 | 16/6/2026 | Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering. | |
| Modificada | Media (5) | 5.1% | — | Winagents Tftp Server | 24/4/2006 | 16/6/2026 | Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request. |