Vulnerabilities
Summary — last 7 days
New vulnerabilities3,234▲ 668 vs. last week
Critical / high1,517▲ 124 vs. last week
New active exploitation (KEV)5▼ 1 vs. last week
Unscored (no CVSS)238▲ 224 vs. last week
10 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5) | 6.9% | 💥 Exploit | Powerdrummer Cftp | 9/23/2011 | 6/16/2026 | cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/session_check.php and certain other files. | |
| Modified | Medium (5) | 38% | 💥 Exploit | Vicftps | 6/8/2009 | 6/16/2026 | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031. | |
| Modified | Medium (5) | 46% | 💥 Exploit | Vicftps | 4/30/2008 | 6/16/2026 | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | High (10) | 9.3% | 💥 Exploit | Vicftps | 2/21/2007 | 6/16/2026 | Stack-based buffer overflow in VicFTPS before 5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long CWD command. | |
| Modified | Low (3.5) | 2.0% | 💥 Exploit | Acftp | 12/27/2006 | 6/16/2026 | acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) PBSZ command. | |
| Modified | Medium (5) | 3.7% | 💥 Exploit | Acftp | 5/9/2006 | 6/16/2026 | acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command. | |
| Modified | Medium (4.6) | 0.46% | — | Ncftp Software Ncftp | 4/20/2004 | 6/16/2026 | NcFTP client 3.1.6 and 3.1.7, when the username and password are included in an FTP URL that is provided on the command line, allows local users to obtain sensitive information via "ps aux," which displays the URL in the process list. | |
| Modified | High (10) | 4.2% | 💥 Exploit | Acftp | 12/31/2002 | 6/16/2026 | acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges. | |
| Modified | Medium (5) | 2.8% | — | Ncftp Software NcftpOpenbsdSUN SolarisSunos | 12/23/2002 | 6/16/2026 | Directory traversal vulnerabilities in multiple FTP clients on UNIX systems allow remote malicious FTP servers to create or overwrite files as the client user via filenames containing /absolute/path or .. (dot dot) sequences. | |
| Modified | High (7.5) | 2.3% | — | Ncftpd Server | 1/1/1999 | 6/16/2026 | Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command. |