Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.10% | — | FroxlorAIPureftpd Pure-ftpdAI | 14/9/2026 | 23/9/2026 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian… | |
| Aplazada | Alta (8.6) | 0.18% | — | Globalscape CuteftpAI | 25/5/2026 | 23/7/2026 | CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and… | |
| Analizada | Alta (8.7) | 0.47% | — | Coreftp Core FTP | 5/4/2026 | 24/7/2026 | Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP… | |
| Analizada | Crítica (9.8) | 0.83% | — | Deftpdf Document Translator | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |
| Analizada | Alta (8.7) | 0.69% | — | Coreftp Core FTP | 30/3/2026 | 17/6/2026 | Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny… | |
| Aplazada | Media (6.7) | 0.44% | — | Coreftp Core FTP LiteAI | 7/2/2026 | 17/6/2026 | Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction. | |
| Aplazada | Media (6.7) | 0.42% | — | Coreftp Core FTP LEAI | 7/2/2026 | 17/6/2026 | Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the application to become unresponsive and… | |
| Aplazada | Alta (8.6) | 1.4% | 💥 Exploit | Netwin SurgeftpAI | 5/8/2025 | 16/6/2026 | Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the underlying system. | |
| Analizada | Crítica (9.3) | 2.6% | 💥 Exploit | Freeftpd | 31/7/2025 | 16/6/2026 | A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PASS command. When an attacker sends a specially crafted password string, the application fails to validate input length, resulting in memory corruption. This can lead to denial of service or arbitrary… | |
| Analizada | Alta (8.6) | 1.6% | 💥 Exploit | Pureftpd Pure-ftpd | 24/10/2024 | 17/6/2026 | pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file. | |
| Modificada | Media (5.5) | 0.30% | — | Globalscape Cuteftp | 2/2/2024 | 17/6/2026 | A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.1) | 78% | — | Enterprisedt Completeftp Server | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the lack of proper validation of a… | |
| Modificada | Alta (7.8) | 0.33% | — | Freesshd Freeftpd | 31/3/2022 | 17/6/2026 | FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | |
| Modificada | Media (5.5) | 0.87% | — | Coreftp Core FTP | 17/2/2022 | 9/7/2026 | Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service. | |
| Modificada | Alta (8.8) | 7.7% | — | Enterprisedt Completeftp Server | 14/2/2022 | 17/6/2026 | CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM. | |
| Modificada | Media (6.5) | 5.4% | 💥 Exploit | Coreftp Core FTP | 10/1/2022 | 17/6/2026 | CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Pureftpd Pure-ftpd | 5/9/2021 | 17/6/2026 | In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are… | |
| Modificada | Crítica (9.8) | 1.3% | — | Coreftp Core FTP | 5/4/2021 | 17/6/2026 | Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username. | |
| Modificada | Alta (7.5) | 1.1% | — | Coreftp Core FTP | 5/4/2021 | 17/6/2026 | Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username. | |
| Modificada | Media (5.5) | 0.25% | — | Coreftp Core FTP | 2/4/2021 | 17/6/2026 | Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Pureftpd Pure-ftpd | 26/12/2020 | 17/6/2026 | Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Pureftpd Pure-ftpdDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+1 | 26/2/2020 | 17/6/2026 | An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member.… | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Pureftpd Pure-ftpdFedoraproject Fedora | 24/2/2020 | 17/6/2026 | An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Pureftpd Pure-ftpdFedoraproject Fedora | 31/12/2019 | 17/6/2026 | In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. | |
| Modificada | Alta (8.8) | 2.8% | 💥 PoC | Freeftpd | 3/12/2019 | 17/6/2026 | freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled). |