Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

98 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)7.6%💥 ExploitPhilippe Jounin Tftpd3221/1/200616/6/2026
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.
ModificadaAlta (7.5)3.8%—Cambridge Computer Corporation Vxtftpsrv22/9/200516/6/2026
Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.
ModificadaAlta (7.8)3.3%—Futuresoft Tftp Server 20001/6/200516/6/2026
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.
ModificadaAlta (10)63%💥 ExploitFuturesoft Tftp Server 20001/6/200516/6/2026
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.
ModificadaAlta (7.5)3.6%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
ModificadaAlta (7.5)4.4%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
ModificadaMedia (5)2.5%—Winagents Tftp ServerAI31/12/200416/6/2026
WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.
ModificadaAlta (10)8.1%💥 ExploitRobotftp Server23/11/200416/6/2026
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.
ModificadaAlta (10)8.3%💥 ExploitNET Integration Technologies Inc. Wvtftp26/10/200416/6/2026
Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.
ModificadaAlta (7.6)5.0%—Smartftp31/12/200316/6/2026
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
ModificadaAlta (7.5)10%💥 ExploitTellurian Tftpdnt20/10/200316/6/2026
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
ModificadaAlta (7.5)5.8%💥 ExploitAtftpd2/7/200316/6/2026
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
ModificadaMedia (5)13%💥 ExploitSolarwinds Tftp Server31/3/200316/6/2026
SolarWinds TFTP server 5.0.55 and earlier allows remote attackers to cause a denial of service (crash) via a large UDP datagram, possibly triggering a buffer overflow.
ModificadaMedia (5)1.8%—Tftp Server31/12/200216/6/2026
tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as com1 or aux.
ModificadaMedia (6.4)7.0%💥 ExploitTftpd3231/12/200216/6/2026
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
ModificadaAlta (7.5)63%💥 ExploitTftpd3231/12/200216/6/2026
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
ModificadaAlta (7.2)0.42%—Remi Lefebvre Advanced Tftp31/12/200216/6/2026
Buffer overflow in Advanced TFTP (atftp) 0.5 and 0.6, if installed setuid or setgid, may allow local users to execute arbitrary code via a long argument to the -g option.
ModificadaMedia (5)13%💥 ExploitSolarwinds Tftp Server4/11/200216/6/2026
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
ModificadaMedia (5)1.7%—Cisco Tftp Server18/10/200116/6/2026
Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command.
ModificadaAlta (7.5)4.2%—IBM Alphaworks Tftp Server20/7/200116/6/2026
Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.
ModificadaBaja (2.1)0.48%—Mindstorm Smartftp Daemon13/6/200016/6/2026
SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.
ModificadaMedia (5.1)1.7%💥 ExploitToxsoft Nextftp3/8/199916/6/2026
Buffer overflow in ToxSoft NextFTP client through CWD command.
ModificadaMedia (6.4)1.6%—TftpLinux Kernel1/9/199716/6/2026
Linux implementations of TFTP would allow access to files outside the restricted directory.
Orbitaley — Vulnerabilidades