Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Biscom Secure File Transfer | 22/10/2020 | 17/6/2026 | Biscom Secure File Transfer (SFT) before 5.1.1082 and 6.x before 6.0.1011 allows user credential theft. | |
| Modificada | Crítica (9.8) | 2.9% | — | Biscom Secure File Transfer | 7/2/2020 | 17/6/2026 | Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server. | |
| Modificada | Media (6.5) | 0.73% | — | Biscom Secure File Transfer | 31/1/2020 | 17/6/2026 | Biscom Secure File Transfer (SFT) 5.0.1050 through 5.1.1067 and 6.0.1000 through 6.0.1003 allows Insecure Direct Object Reference (IDOR) by an authenticated sender because of an error in a file-upload feature. This is fixed in 5.1.1068 and 6.0.1004. | |
| Modificada | Alta (8.1) | 1.1% | — | Biscom Secure File Transfer | 25/1/2018 | 17/6/2026 | Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests. Version 5.0.1050 contains the fix. | |
| Modificada | Media (5.4) | 0.50% | — | Biscom Secure File Transfer | 18/7/2017 | 17/6/2026 | Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that contains standard HTML scripting tags. The resulting script will evaluated by any other authenticated user who views the… | |
| Modificada | Media (4.3) | 0.60% | — | Biscom Secure File Transfer | 18/7/2017 | 17/6/2026 | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's… | |
| Modificada | Media (5.4) | 0.88% | — | Biscom Secure File Transfer | 28/6/2017 | 17/6/2026 | Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a file stored in a Workspace. This issue has been resolved in… | |
| Modificada | Alta (7.2) | 0.82% | — | Accellion Secure File Transfer Appliance | 19/2/2010 | 16/6/2026 | Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack… | |
| Modificada | Media (4.3) | 1.1% | — | Accellion Secure File Transfer Appliance | 19/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs. | |
| Modificada | Alta (9) | 1.7% | — | Accellion Secure File Transfer Appliance | 19/2/2010 | 16/6/2026 | Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by appending them to a request to update the SNMP public community string. | |
| Modificada | Alta (7.8) | 2.8% | — | Accellion Secure File Transfer Appliance | 19/2/2010 | 16/6/2026 | Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. | |
| Modificada | Alta (9) | 2.4% | — | Accellion Secure File Transfer Appliance | 19/2/2010 | 16/6/2026 | Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program. | |
| Modificada | Alta (7.8) | 6.7% | — | Accellion Secure File Transfer Appliance | 19/8/2009 | 16/6/2026 | courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters. | |
| Modificada | Media (4.3) | 1.5% | — | Accellion Secure File Transfer Appliance | 27/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html. |