Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.14% | — | Tftpd32 SEAI | 13/1/2026 | 17/6/2026 | Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions. | |
| Modificada | Media (5) | 2.9% | — | Philippe Jounin Tftpd32 | 13/12/2013 | 17/6/2026 | Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field. | |
| Modificada | Media (4.3) | 0.74% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames." | |
| Modificada | Media (5) | 1.8% | — | Philippe Jounin Tftpd32 | 20/11/2009 | 16/6/2026 | tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226. | |
| Modificada | Media (5) | 3.8% | — | Philippe Jounin Tftpd32 | 28/11/2006 | 16/6/2026 | Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window. | |
| Modificada | Media (5) | 7.6% | — | Philippe Jounin Tftpd32 | 21/1/2006 | 16/6/2026 | Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request. | |
| Modificada | Media (6.4) | 7.0% | — | Tftpd32 | 31/12/2002 | 16/6/2026 | tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. | |
| Modificada | Alta (7.5) | 63% | — | Tftpd32 | 31/12/2002 | 16/6/2026 | Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument. |