Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Khamil Landross AND Zack Jones Eftp | 12/9/2001 | 16/6/2026 | Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Khamil Landross AND Zack Jones Eftp | 12/9/2001 | 16/6/2026 | Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands. | |
| Modificada | Media (5) | 1.3% | — | Khamil Landross AND Zack Jones Eftp | 12/9/2001 | 16/6/2026 | EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection. | |
| Modificada | Media (4.6) | 0.35% | — | Khamil Landross AND Zack Jones Eftp | 12/9/2001 | 16/6/2026 | EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file. | |
| Modificada | Alta (10) | 3.8% | — | Netwin Surgeftp | 4/8/2001 | 16/6/2026 | NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021. | |
| Modificada | Media (4.6) | 0.78% | 💥 Exploit | Netwin DmailNetwin Surgeftp | 20/7/2001 | 16/6/2026 | NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password. | |
| Modificada | Alta (10) | 3.6% | — | Netwin DmailNetwin Surgeftp | 20/7/2001 | 16/6/2026 | Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command. | |
| Modificada | Alta (7.5) | 1.8% | — | Khamil Landross AND Zack Jones Eftp | 14/11/2000 | 16/6/2026 | Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string. | |
| Modificada | Media (5) | 1.9% | — | Khamil Landross AND Zack Jones Eftp | 14/11/2000 | 16/6/2026 | Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server. | |
| Modificada | Media (5) | 0.88% | — | Globalscape Cuteftp | 6/1/2000 | 16/6/2026 | CuteFTP uses weak encryption to store password information in its tree.dat file. |