Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

85 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.4)0.10%—FroxlorAIPureftpd Pure-ftpdAI14/9/202623/9/2026
Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are world readable (the default on Debian…
AplazadaAlta (8.6)0.18%—Globalscape CuteftpAI25/5/202623/7/2026
CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and…
AnalizadaAlta (8.7)0.47%—Coreftp Core FTP5/4/202624/7/2026
Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP…
AnalizadaCrítica (9.8)0.83%—Deftpdf Document Translator31/3/202624/7/2026
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
AnalizadaAlta (8.7)0.69%—Coreftp Core FTP30/3/202617/6/2026
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny…
AplazadaMedia (6.7)0.44%—Coreftp Core FTP LiteAI7/2/202617/6/2026
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.
AplazadaMedia (6.7)0.42%—Coreftp Core FTP LEAI7/2/202617/6/2026
Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the application to become unresponsive and…
AplazadaAlta (8.6)1.4%💥 ExploitNetwin SurgeftpAI5/8/202516/6/2026
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows authenticated users to execute arbitrary system commands via crafted POST requests to `surgeftpmgr.cgi`. This can lead to full remote code execution on the underlying system.
AnalizadaCrítica (9.3)2.6%💥 ExploitFreeftpd31/7/202516/6/2026
A stack-based buffer overflow vulnerability exists in freeFTPd version 1.0.10 and earlier in the handling of the FTP PASS command. When an attacker sends a specially crafted password string, the application fails to validate input length, resulting in memory corruption. This can lead to denial of service or arbitrary…
AnalizadaAlta (8.6)1.6%💥 ExploitPureftpd Pure-ftpd24/10/202417/6/2026
pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.
ModificadaMedia (5.5)0.30%—Globalscape Cuteftp2/2/202417/6/2026
A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the argument Host/Username/Password leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and…
ModificadaCrítica (9.1)78%—Enterprisedt Completeftp Server29/3/202317/6/2026
This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the lack of proper validation of a…
ModificadaAlta (7.8)0.33%—Freesshd Freeftpd31/3/202217/6/2026
FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
ModificadaMedia (5.5)0.87%—Coreftp Core FTP17/2/20229/7/2026
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
ModificadaAlta (8.8)7.7%—Enterprisedt Completeftp Server14/2/202217/6/2026
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.
ModificadaMedia (6.5)5.4%💥 ExploitCoreftp Core FTP10/1/202217/6/2026
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
ModificadaAlta (7.5)4.3%💥 ExploitPureftpd Pure-ftpd5/9/202117/6/2026
In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are…
ModificadaCrítica (9.8)1.3%—Coreftp Core FTP5/4/202117/6/2026
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
ModificadaAlta (7.5)1.1%—Coreftp Core FTP5/4/202117/6/2026
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
ModificadaMedia (5.5)0.25%—Coreftp Core FTP2/4/202117/6/2026
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
ModificadaAlta (7.5)4.5%💥 ExploitPureftpd Pure-ftpd26/12/202017/6/2026
Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.
ModificadaAlta (7.5)6.0%💥 ExploitPureftpd Pure-ftpdDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+126/2/202017/6/2026
An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member.…
ModificadaAlta (7.5)7.1%💥 ExploitPureftpd Pure-ftpdFedoraproject Fedora24/2/202017/6/2026
An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.
ModificadaAlta (7.5)4.4%💥 ExploitPureftpd Pure-ftpdFedoraproject Fedora31/12/201917/6/2026
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
ModificadaAlta (8.8)2.8%💥 PoCFreeftpd3/12/201917/6/2026
freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging is disabled).
Orbitaley — Vulnerabilidades