Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
478 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.41% | — | Xlight FTP ServerAI | 29/7/2026 | 30/7/2026 | Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value by sending a USER command with a username ending in the :adm suffix. Attackers can trigger the admin protocol path within the standard FTP listener… | |
| Aplazada | Crítica (9.2) | 1.0% | — | Xlight FTP ServerAI | 29/7/2026 | 30/7/2026 | Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt stack memory by sending malformed SSH packets when a GCM cipher is negotiated. Attackers can craft packets with an unvalidated length field passed directly to the GCM… | |
| Aplazada | Crítica (9.3) | 0.96% | — | Xlight FTP ServerAI | 29/7/2026 | 30/7/2026 | Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR… | |
| Pendiente de análisis | Crítica (9.1) | 0.66% | — | Ciena Sftp ServerAI | 6/7/2026 | 8/7/2026 | An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an… | |
| Analizada | Alta (8.6) | 2.3% | — | Wftpserver Wing FTP Server | 12/5/2026 | 17/6/2026 | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to inject arbitrary Lua code through the domain admin mydirectory field. Attackers can exploit unsafe serialization of session values into Lua… | |
| Analizada | Alta (7.3) | 0.37% | — | Cerberusftp FTP Server | 27/4/2026 | 17/6/2026 | Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1 | |
| Analizada | Alta (8.6) | 0.21% | — | Xlightftpd Xlight FTP Server | 5/4/2026 | 24/7/2026 | Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration… | |
| Analizada | Media (6.8) | 0.22% | — | Bpftpserver Bulletproof FTP Server | 30/3/2026 | 17/6/2026 | BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the SMTP configuration interface that allows local attackers to crash the application by supplying an oversized string. Attackers can input a buffer of 257 'A' characters in the SMTP Server field and trigger a crash by clicking the Test… | |
| Analizada | Crítica (9.3) | 0.95% | — | Freefloat FTP Server | 22/3/2026 | 17/6/2026 | Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of… | |
| Analizada | Media (6.9) | 0.17% | — | Bpftpserver Bulletproof FTP Server | 22/3/2026 | 17/6/2026 | BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash… | |
| Analizada | Media (6.9) | 0.18% | — | Bpftpserver Bulletproof FTP Server | 22/3/2026 | 17/6/2026 | BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to… | |
| Aplazada | Alta (7.5) | 0.41% | — | Open Tftp Server MultithreadedAI | 12/2/2026 | 17/6/2026 | A heap buffer overflow in the processRequest function of Open TFTP Server MultiThreaded v1.7 allows attackers to cause a Denial of Service (DoS) via a crafted DATA packet. | |
| Aplazada | Alta (8.5) | 0.16% | — | Blackmoon FTP ServerAI | 11/2/2026 | 17/6/2026 | BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to insert malicious code that would execute with LocalSystem account… | |
| Analizada | Media (5.1) | 0.18% | — | Wftpserver Wing FTP Server | 7/2/2026 | 17/6/2026 | Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper… | |
| Analizada | Alta (8.5) | 0.24% | — | Wftpserver Wing FTP Server | 5/2/2026 | 17/6/2026 | Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched with LocalSystem… | |
| Analizada | Alta (8.6) | 1.2% | — | Wftpserver Wing FTP Server | 30/1/2026 | 17/6/2026 | Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system commands. Attackers can leverage the console to send POST requests with malicious commands that trigger operating system execution through the os.execute() function. | |
| Analizada | Media (5.1) | 0.43% | — | Xlightftpd Xlight FTP Server | 15/12/2025 | 17/6/2026 | Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service condition. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Pcman FTP ServerAI | 12/12/2025 | 17/6/2026 | PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access. | |
| Analizada | Crítica (9.3) | 1.6% | — | Easyftp Server Project Easyftp Server | 21/8/2025 | 16/6/2026 | EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer overflow on the stack, potentially… | |
| Analizada | Crítica (9.3) | 3.2% | — | Easyftp Server Project Easyftp Server | 21/8/2025 | 16/6/2026 | EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change Working Directory) command, the server fails to properly validate the length of the input string, allowing attackers to overwrite memory on the stack. This flaw enables… | |
| Aplazada | Alta (8.7) | 0.72% | — | Solar FTP ServerAI | 20/8/2025 | 16/6/2026 | Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing format specifiers is sent, the server crashes due to a read access violation in the __output_1() function of sfsservice.exe. This results in a denial of service (DoS) condition. | |
| Aplazada | Crítica (10) | 1.5% | — | Turbo FTP ServerAI | 5/8/2025 | 16/6/2026 | Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges. | |
| Analizada | Crítica (9.3) | 2.2% | — | Freefloat FTP Server | 5/8/2025 | 16/6/2026 | FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbitrary files to sensitive system directories. The server accepts empty credentials, defaults user access to the root of the C:\ drive, and imposes no restrictions on file type or destination path.… | |
| Analizada | Media (6.9) | 2.5% | — | Freefloat FTP Server | 5/8/2025 | 16/6/2026 | A stack-based buffer overflow vulnerability exists in FreeFloat FTP Server version 1.0.0. The server fails to properly validate input passed to the USER command, allowing remote attackers to overwrite memory and potentially execute arbitrary code. The flaw is triggered by sending an overly long username string, which… | |
| Analizada | Media (4.3) | 63% | ⚠ Explotación activa | Wftpserver Wing FTP Server | 10/7/2025 | 17/6/2026 | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UID cookie. |