Vulnerabilities

Summary — last 7 days

New vulnerabilities3,234▲ 668 vs. last week
Critical / high1,517▲ 124 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
–

10 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (5)6.9%💥 ExploitPowerdrummer Cftp9/23/20116/16/2026
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files.
ModifiedMedium (5)38%💥 ExploitVicftps6/8/20096/16/2026
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.
ModifiedMedium (5)46%💥 ExploitVicftps4/30/20086/16/2026
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (10)9.3%💥 ExploitVicftps2/21/20076/16/2026
Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command.
ModifiedLow (3.5)2.0%💥 ExploitAcftp12/27/20066/16/2026
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command.
ModifiedMedium (5)3.7%💥 ExploitAcftp5/9/20066/16/2026
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command.
ModifiedMedium (4.6)0.46%—Ncftp Software Ncftp4/20/20046/16/2026
NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list.
ModifiedHigh (10)4.2%💥 ExploitAcftp12/31/20026/16/2026
acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.
ModifiedMedium (5)2.8%—Ncftp Software NcftpOpenbsdSUN SolarisSunos12/23/20026/16/2026
Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences.
ModifiedHigh (7.5)2.3%—Ncftpd Server1/1/19996/16/2026
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.
Orbitaley — Vulnerabilities