Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.41% | — | Open Tftp Server MultithreadedAI | 12/2/2026 | 17/6/2026 | A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet. | |
| Modificada | Alta (8.8) | 2.0% | — | Genesys Tftp Server | 10/5/2023 | 17/6/2026 | An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page. | |
| Modificada | Alta (7.8) | 0.44% | — | Open Tftp Server Project Open Tftp Server | 28/10/2020 | 17/6/2026 | Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenTFTPServerMT.exe or the OpenTFTPServerSP.exe binary. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12567. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568. | |
| Modificada | Crítica (9.8) | 2.3% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | |
| Modificada | Crítica (9.8) | 4.4% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. | |
| Modificada | Crítica (9.8) | 2.9% | — | Open Tftp Server Project Open Tftp Server | 23/12/2019 | 17/6/2026 | Heap-based overflow vulnerability in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or possibly execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2008-2161. | |
| Modificada | Alta (7.8) | 58% | — | Ipswitch Tftp Server | 28/12/2014 | 16/6/2026 | Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation. | |
| Modificada | Media (5) | 2.7% | — | Hillstone Software HS Tftp Server | 28/12/2014 | 16/6/2026 | Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation. | |
| Modificada | Media (5) | 11% | — | Solarwinds Tftp Server | 16/6/2010 | 16/6/2026 | SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. | |
| Modificada | Media (5) | 56% | — | Solarwinds Tftp Server | 28/5/2010 | 16/6/2026 | SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request. | |
| Modificada | Media (5) | 5.0% | — | Cisco Tftp Server | 29/3/2010 | 16/6/2026 | Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 11% | — | Solarwinds Tftp Server | 9/9/2009 | 16/6/2026 | SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 55% | — | Netmechanica Netdecision Tftp Server | 20/5/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command. | |
| Modificada | Alta (10) | 65% | — | Tftp Server SP | 12/5/2008 | 16/6/2026 | Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 68% | — | Tftp-server Winagents Tftp Server | 1/4/2008 | 16/6/2026 | Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request. | |
| Modificada | Alta (7.5) | 54% | — | Tallsoft Quick Tftp Server PRO | 1/4/2008 | 16/6/2026 | Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request. | |
| Modificada | Alta (10) | 3.6% | — | Prosysinfo Tftp Server Tftpdwin | 13/5/2007 | 16/6/2026 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | |
| Modificada | Alta (10) | 13% | — | Futuresoft Tftp Server 2000 | 24/3/2007 | 16/6/2026 | Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via a long request on UDP port 69. NOTE: this issue might overlap CVE-2006-4781 or CVE-2005-1812. | |
| Modificada | Alta (10) | 43% | — | D-link Tftp Server | 13/3/2007 | 16/6/2026 | Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.3) | 67% | — | Prosysinfo Tftp Server Tftpdwin | 10/3/2007 | 16/6/2026 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. | |
| Modificada | Alta (7.5) | 55% | — | Prosysinfo Tftp Server Tftpdwin | 23/9/2006 | 16/6/2026 | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 5.7% | — | Futuresoft Tftp Server Multithreaded | 14/9/2006 | 16/6/2026 | Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained… | |
| Modificada | Media (5) | 4.0% | — | Solarwinds Tftp Server | 24/4/2006 | 16/6/2026 | Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering. |