Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.21%—Xlightftpd Xlight FTP Server5/4/202624/7/2026
Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration…
AplazadaAlta (8.5)0.14%—Tftpd32 SEAI13/1/202617/6/2026
Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.
AnalizadaMedia (5.1)0.43%—Xlightftpd Xlight FTP Server15/12/202517/6/2026
Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition.
AplazadaBaja (2.3)0.32%—Phjounin Tftpd64AI12/2/202517/6/2026
A vulnerability was found in phjounin TFTPD64 4.64. It has been declared as problematic. This vulnerability affects unknown code of the component DNS Handler. The manipulation leads to denial of service. The attack needs to be done within the local network. The complexity of an attack is rather high. The exploitation…
ModificadaAlta (7.5)4.2%💥 ExploitXlightftpd Xlight FTP Server19/1/202417/6/2026
A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaAlta (7.8)0.20%—Tftpd64 Project Tftpd6417/2/202317/6/2026
A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be…
ModificadaAlta (8.1)2.2%—Xlightftpd Xlight FTP23/5/202217/6/2026
Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.
ModificadaMedia (5)2.9%—Philippe Jounin Tftpd3213/12/201317/6/2026
Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.
ModificadaMedia (6.5)1.9%—Xlightftpd Xlight FTP Server12/7/201016/6/2026
Directory traversal vulnerability in the SFTP/SSH2 virtual server in Xlight FTP Server 3.5.0, 3.5.5, and possibly other versions before 3.6 allows remote authenticated users to read, overwrite, or delete arbitrary files via .. (dot dot) sequences in the (1) ls, (2) rm, (3) rename, and other unspecified commands.
ModificadaMedia (6.8)2.0%💥 ExploitXlightftpd Xlight FTP Server22/4/201016/6/2026
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.
ModificadaMedia (4.3)0.74%—Philippe Jounin Tftpd3220/11/200916/6/2026
Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames."
ModificadaMedia (5)1.8%—Philippe Jounin Tftpd3220/11/200916/6/2026
tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.
ModificadaMedia (6.8)3.6%💥 ExploitBootmanage AdministratorBootmanage Tftpd20/3/200816/6/2026
Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename.
ModificadaAlta (10)3.6%💥 ExploitProsysinfo Tftp Server Tftpdwin13/5/200716/6/2026
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.
ModificadaAlta (7.3)68%💥 ExploitProsysinfo Tftp Server Tftpdwin10/3/200716/6/2026
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.
ModificadaMedia (5)3.8%—Philippe Jounin Tftpd3228/11/200616/6/2026
Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window.
ModificadaAlta (7.5)55%💥 ExploitProsysinfo Tftp Server Tftpdwin23/9/200616/6/2026
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)7.6%💥 ExploitPhilippe Jounin Tftpd3221/1/200616/6/2026
Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.
ModificadaAlta (7.5)3.6%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
ModificadaAlta (7.5)4.4%💥 ExploitYepyep Mtftpd2/5/200516/6/2026
Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote attackers to execute arbitrary code via the CWD command.
ModificadaAlta (7.5)10%💥 ExploitTellurian Tftpdnt20/10/200316/6/2026
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a long filename.
ModificadaAlta (7.5)5.8%💥 ExploitAtftpd2/7/200316/6/2026
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
ModificadaMedia (6.4)7.0%💥 ExploitTftpd3231/12/200216/6/2026
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
ModificadaAlta (7.5)63%💥 ExploitTftpd3231/12/200216/6/2026
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
Orbitaley — Vulnerabilidades