Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.21% | — | Xlightftpd Xlight FTP Server | 5/4/2026 | 24/7/2026 | Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration… | |
| Aplazada | Alta (8.5) | 0.14% | — | Tftpd32 SEAI | 13/1/2026 | 17/6/2026 | Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions. | |
| Analizada | Media (5.1) | 0.43% | — | Xlightftpd Xlight FTP Server | 15/12/2025 | 17/6/2026 | Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition. | |
| Aplazada | Baja (2.3) | 0.32% | — | Phjounin Tftpd64AI | 12/2/2025 | 17/6/2026 | A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Xlightftpd Xlight FTP Server | 19/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.8) | 0.20% | — | Tftpd64 Project Tftpd64 | 17/2/2023 | 17/6/2026 | A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be… | |
| Modificada | Alta (8.1) | 2.2% | — | Xlightftpd Xlight FTP | 23/5/2022 | 17/6/2026 | Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code. | |
| Modificada | Media (5) | 2.9% | — | Philippe Jounin Tftpd32 | 13/12/2013 | 17/6/2026 | Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field. | |
| Modificada | Media (6.5) | 1.9% | — | Xlightftpd Xlight FTP Server | 12/7/2010 | 16/6/2026 | Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Xlightftpd Xlight FTP Server | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command. | |
| Modificada | Media (4.3) | 0.74% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames." | |
| Modificada | Media (5) | 1.8% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226. | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Bootmanage AdministratorBootmanage Tftpd | 20/3/2008 | 16/6/2026 | Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename. | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 13/5/2007 | 16/6/2026 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | |
| Modificada | Alta (7.3) | 68% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 10/3/2007 | 16/6/2026 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. | |
| Modificada | Media (5) | 3.8% | — | Philippe Jounin Tftpd32 | 28/11/2006 | 16/6/2026 | Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Prosysinfo Tftp Server Tftpdwin | 23/9/2006 | 16/6/2026 | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Philippe Jounin Tftpd32 | 21/1/2006 | 16/6/2026 | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Yepyep Mtftpd | 2/5/2005 | 16/6/2026 | Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Tellurian Tftpdnt | 20/10/2003 | 16/6/2026 | Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename. | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Atftpd | 2/7/2003 | 16/6/2026 | Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename. | |
| Modificada | Media (6.4) | 7.0% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | |
| Modificada | Alta (7.5) | 63% | 💥 Exploit | Tftpd32 | 31/12/2002 | 16/6/2026 | Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. |