Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 1.5% | — | Monstaftp Monsta FTPAI | 8/7/2026 | 14/7/2026 | Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist check in the isBlockedIP() function, which fails to detect embedded IPv4 addresses within IPv4-mapped IPv6 addresses. An unauthenticated attacker can obtain a CSRF token from… | |
| Analizada | Crítica (9.3) | 73% | — | Monstaftp Monsta FTP | 7/11/2025 | 17/6/2026 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. | |
| Modificada | Crítica (9.8) | 1.4% | — | Monstaftp Monsta FTP | 26/4/2022 | 17/6/2026 | Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF). | |
| Modificada | Crítica (9.8) | 2.1% | — | Monstaftp Monsta FTP | 26/4/2022 | 17/6/2026 | Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server. | |
| Modificada | Crítica (9.8) | 2.6% | — | Monstaftp Monsta FTP | 1/7/2020 | 17/6/2026 | Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments. | |
| Modificada | Crítica (9.8) | 1.3% | — | Monstaftp Monsta FTP | 1/7/2020 | 17/6/2026 | Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services. | |
| Modificada | Media (6.1) | 0.70% | — | Monstaftp Monsta FTP | 1/7/2020 | 17/6/2026 | Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. |