Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.15% | — | Zftp ClientAI | 28/3/2026 | 17/6/2026 | zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connections that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized NAME value exceeding the 80-byte buffer allocated in strcpy_chk to overwrite the… | |
| Aplazada | Alta (8.6) | 0.66% | — | Ayukov Nftp ClientAI | 18/2/2026 | 17/6/2026 | Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150. | |
| Aplazada | Alta (7.1) | 0.42% | — | Fetch FTP ClientAI | 30/12/2025 | 17/6/2026 | Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the application. | |
| Aplazada | Alta (8.5) | 0.51% | — | Gekko Manager FTP ClientAI | 21/8/2025 | 16/6/2026 | Gekko Manager FTP Client <= 0.77 contains a stack-based buffer overflow in its FTP directory listing parser. When processing a server response to a LIST command, the client fails to properly validate the length of filenames. A crafted response containing an overly long filename can overwrite the Structured Exception… | |
| Aplazada | Alta (8.5) | 0.51% | — | Seagull FTP ClientAI | 21/8/2025 | 16/6/2026 | Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long filename, the application fails to properly validate input length,… | |
| Aplazada | Alta (8.7) | 1.1% | — | Winaxe FTP ClientAI | 15/7/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the WinaXe FTP Client version 7.7 within the FTP banner parsing functionality, WCMDPA10.dll. When the client connects to a remote FTP server and receives an overly long '220 Server Ready' response, the vulnerable component responsible for parsing the banner overflows a stack… | |
| Modificada | Alta (10) | 7.7% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the SaveSettings method. | |
| Modificada | Alta (10) | 6.3% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | Directory traversal vulnerability in the rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to execute arbitrary code via unspecified vectors to the StartLog method. | |
| Modificada | Alta (10) | 5.7% | — | Attachmate Reflection FTP Client | 6/2/2015 | 17/6/2026 | The rftpcom.dll ActiveX control in Attachmate Reflection FTP Client before 14.1.429 allows remote attackers to cause a denial of service (memory corruption) and execute arbitrary code via vectors related to the (1) GetGlobalSettings or (2) GetSiteProperties3 methods, which triggers a dereference of an arbitrary memory… | |
| Modificada | Media (6.8) | 2.8% | — | Attachmate Reflection FTP Client | 27/1/2015 | 17/6/2026 | Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response. | |
| Modificada | Alta (9.3) | 1.6% | — | 3dftp 3d-ftp Client | 21/8/2010 | 16/6/2026 | Directory traversal vulnerability in SiteDesigner Technologies, Inc. 3D-FTP Client 9.0 build 2, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. | |
| Modificada | Alta (9.3) | 1.5% | — | Portaplus Porta+ FTP Client | 20/8/2010 | 16/6/2026 | Directory traversal vulnerability in Porta+ FTP Client 4.1, and possibly other versions, allows remote FTP servers to overwrite arbitrary files via a directory traversal sequences in a filename. | |
| Modificada | Alta (9.3) | 1.4% | — | Softx FTP Client | 20/8/2010 | 16/6/2026 | Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via "..\" (dot dot backslash) sequences in a filename. | |
| Modificada | Alta (9.3) | 4.6% | — | Bpftp Bulletproof FTP Client | 30/12/2008 | 16/6/2026 | Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753. | |
| Modificada | Alta (9.3) | 7.5% | — | Bpftp Bulletproof FTP Client | 30/12/2008 | 16/6/2026 | Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry with a long host name, which appears as a host parameter within the quick-connect bar. | |
| Modificada | Alta (9.3) | 3.0% | — | 3dftp 3d-ftp Client | 23/6/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in the FTP client in 3D-FTP Client 8.01 (8.0 build 1) allow remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a (1) LIST or (2) MLSD command. | |
| Modificada | Media (5) | 0.94% | — | Junkie FTP Client | 10/1/2005 | 16/6/2026 | The ftp_retr function in junkie 0.3.1 allows remote malicious FTP servers to overwrite arbitrary files via .. (dot dot) sequences in a filename. | |
| Modificada | Alta (10) | 2.1% | — | Junkie FTP Client | 10/1/2005 | 16/6/2026 | The gui_popup_view_fly function in gui_tview_popup.c for junkie 0.3.1 allows remote malicious FTP servers to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (6.4) | 4.3% | — | Electrasoft FTP Client | 31/12/2003 | 16/6/2026 | Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner. | |
| Modificada | Alta (10) | 3.5% | — | MIT Kerberos FTP ClientRedhat LinuxMandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake Linux | 19/2/2003 | 16/6/2026 | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. | |
| Modificada | Alta (7.5) | 4.2% | — | Browseftp Client | 31/12/2002 | 16/6/2026 | Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply. | |
| Modificada | Media (4.6) | 0.35% | — | Gftp FTP Client | 5/9/1999 | 16/6/2026 | gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file. |