Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.2% | — | Cerberusftp FTP Server | 14/1/2020 | 17/6/2026 | Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing… | |
| Modificada | Media (5.4) | 0.68% | — | Cerberusftp FTP Server | 14/1/2020 | 17/6/2026 | The zip API endpoint in Cerberus FTP Server 8 allows an authenticated attacker without zip permission to use the zip functionality via an unrestricted API endpoint. Improper permission verification occurs when calling the file/ajax_download_zip/zip_name endpoint. The result is that a user without permissions can zip… | |
| Modificada | Media (6.1) | 1.2% | — | Cerberusftp FTP Server | 13/1/2020 | 17/6/2026 | Reflected XSS through an IMG element in Cerberus FTP Server prior to versions 11.0.1 and 10.0.17 allows a remote attacker to execute arbitrary JavaScript or HTML via a crafted public folder URL. This occurs because of the folder_up.png IMG element not properly sanitizing user-inserted directory paths. The path… | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | |
| Modificada | Crítica (9.8) | 4.4% | 💥 PoC | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | |
| Modificada | Crítica (9.8) | 2.9% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161. | |
| Modificada | Media (5.4) | 2.3% | — | Solarwinds Serv-u FTP Server | 18/12/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. | |
| Modificada | Media (5.4) | 6.4% | — | Solarwinds Serv-u FTP Server | 16/12/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. | |
| Modificada | Media (6.5) | 3.2% | — | Solarwinds Serv-u FTP Server | 16/12/2019 | 17/6/2026 | A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Enterprisedt Completeftp Server | 2/10/2019 | 17/6/2026 | EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash. | |
| Modificada | Alta (8.8) | 66% | 💥 Exploit | Solarwinds Serv-u FTP ServerSolarwinds Serv-u MFT Server | 17/6/2019 | 17/6/2026 | A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | |
| Modificada | Crítica (9.1) | 4.0% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory. | |
| Modificada | Alta (7.5) | 4.7% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose path names on the host operating system. | |
| Modificada | Crítica (9.8) | 2.9% | — | Ipswitch WS FTP Server | 11/6/2019 | 17/6/2026 | An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversal vulnerability using the SCP protocol. Attackers who leverage this flaw could also obtain remote code execution by crafting a payload that abuses the SITE command… | |
| Modificada | Media (5.3) | 2.0% | — | Progress WS FTP Server | 11/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose WS_FTP usernames as well as filenames. | |
| Modificada | Alta (7.8) | 0.60% | — | Solarwinds Serv-u FTP Server | 7/6/2019 | 17/6/2026 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have… | |
| Modificada | Media (6.5) | 11% | 💥 Exploit | Southrivertech Titan FTP Server | 3/6/2019 | 17/6/2026 | A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandler.ashx) by using a \..\..\ technique, arbitrary files can be loaded in the server response outside the root directory. | |
| Modificada | Crítica (9.8) | 1.6% | — | Wifi FTP Server Project Wifi FTP Server | 22/4/2019 | 17/6/2026 | An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/password of a valid user via /data/data/com.medhaapps.wififtpserver/shared_prefs/com.medhaapps.wififtpserver_preferences.xml | |
| Modificada | Media (4.8) | 5.4% | — | Solarwinds Serv-u FTP Server | 21/3/2019 | 17/6/2026 | SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter. | |
| Modificada | Alta (7.2) | 8.1% | — | Solarwinds Serv-u FTP Server | 21/3/2019 | 17/6/2026 | SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Theolivetree FTP Server | 6/3/2019 | 17/6/2026 | The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers to cause a denial of service via a client that makes many connection attempts and drops certain packets. | |
| Modificada | Crítica (9.8) | 4.5% | — | Pcman FTP Server | 20/11/2018 | 19/8/2026 | Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command. | |
| Modificada | Media (6.1) | 5.4% | — | Accellion FTP Server | 13/7/2018 | 17/6/2026 | Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting. |