Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.3)0.47%—VsftpdAIDlink Dir-842AI15/8/202620/8/2026
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The…
AplazadaBaja (2.3)0.29%—Trendnet Tew-813druAIVsftpdAI14/8/202614/8/2026
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability…
AplazadaMedia (5.5)0.29%—Totolink Ex200AIVsftpdAI9/6/202623/7/2026
A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation results in least privilege violation. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for…
AplazadaBaja (2.1)0.21%—Totolink Cp450AIVsftpdAI8/6/202623/7/2026
A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.21%—Totolink Ac1200 T8AIVsftpdAI8/6/202623/7/2026
A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least privilege violation. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
AplazadaMedia (6.5)0.82%—VsftpdAI14/1/202630/6/2026
A flaw was found in vsftpd. This vulnerability allows a denial of service (DoS) via an integer overflow in the ls command parameter parsing, triggered by a remote, authenticated attacker sending a crafted STAT command with a specific byte sequence.
AplazadaMedia (6.4)0.16%—Trendnet Tew-822dreAIVsftpdAI9/8/202517/6/2026
A vulnerability was found in TRENDnet TEW-822DRE FW103B02. It has been classified as problematic. This affects an unknown part of the component vsftpd. The manipulation leads to least privilege violation. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be…
ModificadaAlta (7.5)3.2%—Vsftpd Project Vsftpd22/8/202317/6/2026
VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.
ModificadaAlta (7.4)2.0%—F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+123/3/202217/6/2026
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to…
ModificadaCrítica (9.8)96%—Vsftpd Project VsftpdDebian Linux27/11/201916/6/2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
ModificadaMedia (5)6.8%—OpensuseVsftpd Project Vsftpd28/1/201517/6/2026
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
ModificadaMedia (4)74%—Vsftpd Project VsftpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+22/3/201116/6/2026
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.
ModificadaAlta (7.5)1.7%—Provider4u Vsftpd Webmin Module30/12/200916/6/2026
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."
ModificadaAlta (7.1)3.7%—Redhat Vsftpd9/7/200816/6/2026
Memory leak in a certain Red Hat deployment of vsftpd before 2.0.5 on Red Hat Enterprise Linux (RHEL) 3 and 4, when PAM is used, allows remote attackers to cause a denial of service (memory consumption) via a large number of invalid authentication attempts within the same session, a different vulnerability than…
ModificadaMedia (5)2.1%—Beasts Vsftpd31/12/200416/6/2026
vsftpd before 1.2.2, when under heavy load, allows attackers to cause a denial of service (crash) via a SIGCHLD signal during a malloc or free call, which is not re-entrant.
ModificadaMedia (5)1.2%—Beasts Vsftpd3/2/200416/6/2026
vsftpd 1.1.3 generates different error messages depending on whether or not a valid username exists, which allows remote attackers to identify valid usernames.