Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.32%—Melag FTP Server24/6/202217/6/2026
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
ModificadaMedia (6.5)1.5%—Melag FTP Server24/6/202217/6/2026
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP server apply.
ModificadaAlta (8.8)2.1%—Melag FTP Server24/6/202217/6/2026
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
ModificadaMedia (5.3)0.97%—Melag FTP Server24/6/202217/6/2026
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
ModificadaAlta (7.8)0.26%—Southrivertech Titan FTP Server Nextgen19/6/202217/6/2026
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands locally as NT AUTHORITY\SYSTEM, aka NX-I674…
ModificadaCrítica (9.8)1.7%—Southrivertech Titan FTP Server Nextgen19/6/202217/6/2026
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue 1). NOTE: as of 2022-06-21, the…
ModificadaAlta (8.8)7.7%—Enterprisedt Completeftp Server14/2/202217/6/2026
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.
ModificadaMedia (6.1)1.8%💥 ExploitCerberusftp FTP Server10/6/202117/6/2026
The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
ModificadaMedia (4.8)1.2%—Solarwinds Serv-u FTP ServerSolarwinds Serv-u MFT Server5/5/202117/6/2026
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
ModificadaMedia (6.1)5.8%💥 ExploitWftpserver Wing FTP Server26/1/202117/6/2026
An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execution of (sandboxed) arbitrary HTML and JavaScript in the user's browser.
ModificadaAlta (7.8)0.44%—Open Tftp Server Project Open Tftp Server28/10/202017/6/2026
Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenTFTPServerMT.exe or the OpenTFTPServerSP.exe binary.
ModificadaCrítica (9.8)1.6%—Solarwinds Serv-u FTP Server5/7/202017/6/2026
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
ModificadaCrítica (9.8)1.6%—Solarwinds Serv-u FTP Server5/7/202017/6/2026
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
ModificadaCrítica (9.8)7.0%—Solarwinds Serv-u FTP Server5/7/202017/6/2026
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
ModificadaCrítica (9.8)1.6%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for executing programs when certain events are triggered.
ModificadaAlta (8.8)1.0%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. It doesn't enforce permission over Windows Symlinks or Junctions. As a result, a low-privileged user (non-admin) can craft a Junction Link in a directory he has full control of, breaking out of the sandbox.
ModificadaAlta (8.8)0.50%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, admin ones included; Create/Delete users; Enable/Disable Services; Set a rogue update proxy; and Shutdown the server.
ModificadaCrítica (9.8)0.91%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.
ModificadaMedia (6.1)0.68%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Web Interface has Multiple Stored and Reflected XSS. GetInheritedProperties is Reflected via the groups parameter. GetUserInfo is Reflected via POST data. SetUserInfo is Stored via the general parameter.
ModificadaAlta (7.5)0.93%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
ModificadaMedia (6.1)0.68%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The User Web Interface has Multiple Stored and Reflected XSS issues. Collaborate is Reflected via the filename parameter. Collaborate is Stored via the displayname parameter. Deletemultiple is Reflected via the files parameter. Share is Reflected…
ModificadaAlta (8.8)0.50%—Provideserver Provide FTP Server12/4/202017/6/2026
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for uploading and deleting files and directories.
ModificadaAlta (7.8)0.58%💥 PoCWftpserver Wing FTP Server7/3/202017/6/2026
An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may view the contents of the session and session_admin directories, which expose active session cookies within the Wing FTP HTTP interface and administration panel. These…
ModificadaAlta (7.8)0.81%💥 PoCWftpserver Wing FTP Server7/3/202017/6/2026
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local users to arbitrarily create FTP users with full privileges, and escalate privileges within the operating system by modifying system files.
ModificadaAlta (7.8)0.43%—Wftpserver Wing FTP Server7/3/202017/6/2026
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to…