Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)11%💥 ExploitKhamil Landross AND Zack Jones Eftp12/9/200116/6/2026
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.
ModificadaAlta (7.5)8.0%💥 ExploitKhamil Landross AND Zack Jones Eftp12/9/200116/6/2026
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
ModificadaMedia (5)1.3%—Khamil Landross AND Zack Jones Eftp12/9/200116/6/2026
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.
ModificadaMedia (4.6)0.35%—Khamil Landross AND Zack Jones Eftp12/9/200116/6/2026
EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.
ModificadaAlta (10)3.8%—Netwin Surgeftp4/8/200116/6/2026
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
ModificadaMedia (4.6)0.78%💥 ExploitNetwin DmailNetwin Surgeftp20/7/200116/6/2026
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.
ModificadaAlta (10)3.6%—Netwin DmailNetwin Surgeftp20/7/200116/6/2026
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.
ModificadaAlta (7.5)1.8%—Khamil Landross AND Zack Jones Eftp14/11/200016/6/2026
Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.
ModificadaMedia (5)1.9%—Khamil Landross AND Zack Jones Eftp14/11/200016/6/2026
Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.
ModificadaMedia (5)0.88%—Globalscape Cuteftp6/1/200016/6/2026
CuteFTP uses weak encryption to store password information in its tree.dat file.
Orbitaley — Vulnerabilidades