Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.0% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session. | |
| Modificada | Media (4.3) | 0.92% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function having an ENOTCONN error, a different vulnerability than CVE-2010-3494. | |
| Modificada | Media (4.3) | 1.4% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, a different vulnerability than… | |
| Modificada | Media (4) | 1.3% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt. | |
| Modificada | Alta (7.5) | 1.5% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (6.5) | 2.0% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command. | |
| Modificada | Media (6.5) | 1.8% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as… | |
| Modificada | Media (4) | 1.7% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command. | |
| Modificada | Media (5) | 2.2% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command. | |
| Modificada | Media (5) | 1.1% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command. | |
| Modificada | Alta (7.5) | 2.1% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Media (6.5) | 1.9% | — | G.rodola Pyftpdlib | 19/10/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR command. | |
| Modificada | Media (6.5) | 1.9% | — | Xlightftpd Xlight FTP Server | 12/7/2010 | 16/6/2026 | Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands. | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Open-ftpd | 2/7/2010 | 16/6/2026 | Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first. | |
| Modificada | Alta (7.5) | 1.8% | — | Debian Pyftpd | 16/6/2010 | 16/6/2026 | auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote attackers to read arbitrary files from the FTP server. | |
| Modificada | Baja (3.6) | 0.30% | — | Radovan Garabik Pyftpd | 16/6/2010 | 16/6/2026 | Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Xlightftpd Xlight FTP Server | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command. | |
| Modificada | Media (5) | 1.4% | — | Jesse Smith Bftpd | 7/1/2010 | 16/6/2026 | The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 1.7% | — | Provider4u Vsftpd Webmin Module | 30/12/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues." | |
| Modificada | Media (4.3) | 0.74% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames." | |
| Modificada | Media (5) | 1.8% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226. | |
| Modificada | Media (5.8) | 5.7% | — | Proftpd | 28/10/2009 | 16/6/2026 | The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname… | |
| Modificada | Media (6.8) | 0.58% | — | Luke Mewburn Tnftpd | 21/8/2009 | 16/6/2026 | tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server. | |
| Modificada | Alta (9) | 5.3% | 💥 Exploit | Raidenftpd | 19/2/2009 | 16/6/2026 | Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service (crash) or execute arbitrary code via long (1) CWD and (2) MLST commands. | |
| Modificada | Media (6.8) | 16% | 💥 Exploit | Proftpd | 12/2/2009 | 16/6/2026 | ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres. |