Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.2%—Cerberusftp FTP Server14/1/202017/6/2026
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing…
ModificadaMedia (5.4)0.68%—Cerberusftp FTP Server14/1/202017/6/2026
The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip…
ModificadaMedia (6.1)1.2%—Cerberusftp FTP Server13/1/202017/6/2026
Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path…
ModificadaCrítica (9.8)2.3%—Open Tftp Server Project Open Tftp Server23/12/201917/6/2026
Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567.
ModificadaCrítica (9.8)2.3%—Open Tftp Server Project Open Tftp Server23/12/201917/6/2026
Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.
ModificadaCrítica (9.8)2.3%—Open Tftp Server Project Open Tftp Server23/12/201917/6/2026
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
ModificadaCrítica (9.8)4.4%💥 PoCOpen Tftp Server Project Open Tftp Server23/12/201917/6/2026
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
ModificadaCrítica (9.8)2.9%—Open Tftp Server Project Open Tftp Server23/12/201917/6/2026
Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161.
ModificadaMedia (5.4)2.3%—Solarwinds Serv-u FTP Server18/12/201917/6/2026
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
ModificadaMedia (5.4)6.4%—Solarwinds Serv-u FTP Server16/12/201917/6/2026
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
ModificadaMedia (6.5)3.2%—Solarwinds Serv-u FTP Server16/12/201917/6/2026
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
ModificadaMedia (4.3)3.7%💥 ExploitEnterprisedt Completeftp Server2/10/201917/6/2026
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
ModificadaAlta (8.8)66%💥 ExploitSolarwinds Serv-u FTP ServerSolarwinds Serv-u MFT Server17/6/201917/6/2026
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
ModificadaCrítica (9.1)4.0%—Ipswitch WS FTP Server11/6/201917/6/2026
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory.
ModificadaAlta (7.5)4.7%—Ipswitch WS FTP Server11/6/201917/6/2026
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose path names on the host operating system.
ModificadaCrítica (9.8)2.9%—Ipswitch WS FTP Server11/6/201917/6/2026
An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversal vulnerability using the SCP protocol. Attackers who leverage this flaw could also obtain remote code execution by crafting a payload that abuses the SITE command…
ModificadaMedia (5.3)2.0%—Progress WS FTP Server11/6/201917/6/2026
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames.
ModificadaAlta (7.8)0.60%—Solarwinds Serv-u FTP Server7/6/201917/6/2026
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have…
ModificadaMedia (6.5)11%💥 ExploitSouthrivertech Titan FTP Server3/6/201917/6/2026
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory.
ModificadaCrítica (9.8)1.6%—Wifi FTP Server Project Wifi FTP Server22/4/201917/6/2026
An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid user via /data/data/com.medhaapps.wififtpserver/shared_prefs/com.medhaapps.wififtpserver_preferences.xml
ModificadaMedia (4.8)5.4%—Solarwinds Serv-u FTP Server21/3/201917/6/2026
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
ModificadaAlta (7.2)8.1%—Solarwinds Serv-u FTP Server21/3/201917/6/2026
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
ModificadaAlta (7.5)8.3%💥 ExploitTheolivetree FTP Server6/3/201917/6/2026
The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets.
ModificadaCrítica (9.8)4.5%—Pcman FTP Server20/11/201819/8/2026
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
ModificadaMedia (6.1)5.4%—Accellion FTP Server13/7/201817/6/2026
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.