Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.38% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacker to add or delete the file types that are used on the server via RAPR/TriggerServerFunction.html. | |
| Modificada | Media (6.1) | 0.72% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A HTTP Response Splitting vulnerability was identified in the Web Settings Component of Web File Manager in Rumpus FTP Server 8.2.9.1. A successful exploit can result in stored XSS, website defacement, etc. via ExtraHTTPHeader to RAPR/WebSettingsGeneralSet.html. | |
| Modificada | Media (6.5) | 0.43% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could allow an attacker to delete, create, and update the upload forms via RAPR/TriggerServerFunction.html. | |
| Modificada | Media (5.4) | 0.37% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an attacker to whitelist or block any IP address via RAPR/BlockedClients.html. | |
| Modificada | Media (4.3) | 0.38% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can create/update event notices via RAPR/EventNoticesSet.html. | |
| Modificada | Media (6.1) | 0.77% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A Cookie based reflected XSS exists in the Web File Manager of Rumpus FTP Server 8.2.9.1, related to RumpusLoginUserName and snp. | |
| Modificada | Alta (7.1) | 0.37% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html. | |
| Modificada | Media (6.5) | 0.43% | — | Maxum Rumpus FTP | 10/2/2020 | 17/6/2026 | A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can Create and Delete accounts via RAPR/TriggerServerFunction.html. | |
| Modificada | Media (4.6) | 0.40% | — | Maxum Development Corporation Rumpus FTP Server | 19/1/2007 | 16/6/2026 | Untrusted search path vulnerability in Rumpus 5.1 and earlier allows local users to gain privileges via a modified PATH that points to a malicious ipfw program. | |
| Modificada | Media (6.5) | 3.8% | — | Maxum Development Corporation Rumpus FTP Server | 19/1/2007 | 16/6/2026 | Multiple heap-based buffer overflows in rumpusd in Rumpus 5.1 and earlier (1) allow remote authenticated users to execute arbitrary code via a long LIST command and other unspecified requests to the FTP service, and (2) allow remote attackers to execute arbitrary code via unspecified requests to the HTTP service. | |
| Modificada | Media (4.6) | 0.40% | — | Maxum Development Corporation Rumpus FTP Server | 19/1/2007 | 16/6/2026 | Rumpus 5.1 and earlier has weak permissions for certain files and directories under /usr/local/Rumpus, including the configuration file, which allows local users to have an unknown impact by creating, modifying, or deleting files. | |
| Modificada | Media (5) | 3.2% | — | Maxum Development Corporation Rumpus FTP Server | 20/9/2001 | 16/6/2026 | Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating a directory name of a specific length. | |
| Modificada | Alta (7.5) | 1.5% | — | Maxum Development Corporation Rumpus FTP Server | 20/9/2001 | 16/6/2026 | Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 stores passwords in plaintext in the "Rumpus User Database" file in the prefs folder, which could allow attackers to gain privileges on the server. | |
| Modificada | Baja (2.1) | 0.96% | — | Maxum Development Corporation Rumpus FTP Server | 20/9/2001 | 16/6/2026 | Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir command that specifies a large number of sub-folders. |