Записи crushftp
17 опубликованных записей вендора crushftp.
Профиль для исследователя
- Попали в KEV
- 3 · 17,6 %
- С эксплойтом
- 4 · 23,5 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 11,8 %
- Медиана: публикация → KEV
- 4 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-40 Path Traversal: '\\UNC\share\name\' (Windows UNC Share)1
- CWE-420 Unprotected Alternate Channel1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2024-4040Готовый эксплойт | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Критическая10,0 | KEV | 99,5 % | 22 апр. 2024 г. |
99Срочно | CVE-2025-31161Готовый эксплойт | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instacrushftp · crushftp · CWE-305 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2025 г. |
97Срочно | CVE-2025-54309Готовый эксплойт | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Критическая9,8 | KEV | 94,9 % | 18 июл. 2025 г. |
64На этой неделе | CVE-2023-43177Готовый эксплойт | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.crushftp · crushftp · CWE-913 | Критическая9,8 | — | 81,8 % | 17 нояб. 2023 г. |
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,3 % | 18 дек. 2023 г. |
39Наблюдать | CVE-2017-14035Эксплойта нет | CrushFTP 8.x before 8.2.0 has a serialization vulnerability.crushftp · crushftp · CWE-502 | Критическая9,8 | — | 1,6 % | 30 авг. 2017 г. |
39Наблюдать | CVE-2024-53552Эксплойта нет | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.crushftp · crushftp · CWE-640 | Критическая9,8 | — | 0,8 % | 9 дек. 2024 г. |
25Наблюдать | CVE-2025-32103Эксплойта нет | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accrushftp · crushftp · CWE-40 | Средняя5,0 | — | 18,1 % | 15 апр. 2025 г. |
24Наблюдать | CVE-2017-14038Эксплойта нет | CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.crushftp · crushftp · CWE-601 | Средняя6,1 | — | 0,7 % | 30 авг. 2017 г. |
24Наблюдать | CVE-2017-14036Эксплойта нет | CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.crushftp · crushftp · CWE-79 | Средняя6,1 | — | 0,7 % | 30 авг. 2017 г. |
24Наблюдать | CVE-2017-14037Эксплойта нет | CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.crushftp · crushftp · CWE-93 | Средняя6,1 | — | 0,7 % | 30 авг. 2017 г. |
24Наблюдать | CVE-2018-18288Эксплойта нет | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.crushftp · crushftp · CWE-601 | Средняя6,1 | — | 0,6 % | 25 дек. 2019 г. |
24Наблюдать | CVE-2024-22910Эксплойта нет | Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloacrushftp · crushftp · CWE-79 | Средняя6,1 | — | 0,5 % | 14 мая 2024 г. |
24Наблюдать | CVE-2025-63419Proof of concept | Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.crushftp · crushftp · CWE-79 | Средняя6,1 | — | 0,2 % | 12 нояб. 2025 г. |
23Наблюдать | CVE-2025-32102Эксплойта нет | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request crushftp · crushftp · CWE-918 | Средняя5,0 | — | 9,4 % | 15 апр. 2025 г. |
19Наблюдать | CVE-2021-44076Эксплойта нет | An issue was discovered in CrushFTP 9.crushftp · crushftp · CWE-79 | Средняя4,8 | — | 0,7 % | 15 сент. 2022 г. |
16Наблюдать | CVE-2025-63420Proof of concept | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pecrushftp · crushftp · CWE-79 | Средняя4,1 | — | 0,3 % | 7 нояб. 2025 г. |
- CVE-2024-4040100Срочно
Unauthenticated arbitrary file read and remote code execution in CrushFTP
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %crushftp · crushftp22 апр. 2024 г.
- CVE-2025-3116199Срочно
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %crushftp · crushftp3 апр. 2025 г.
- CVE-2025-5430997Срочно
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %crushftp · crushftp18 июл. 2025 г.
- CVE-2023-4317764На этой неделе
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %crushftp · crushftp17 нояб. 2023 г.
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 93 %ssh · ssh18 дек. 2023 г.
- CVE-2017-1403539Наблюдать
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %crushftp · crushftp30 авг. 2017 г.
- CVE-2024-5355239Наблюдать
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %crushftp · crushftp9 дек. 2024 г.
- CVE-2025-3210325Наблюдать
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files ac
СредняяCVSS 5,0Эксплойта нетEPSS 18 %crushftp · crushftp15 апр. 2025 г.
- CVE-2017-1403824Наблюдать
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crushftp · crushftp30 авг. 2017 г.
- CVE-2017-1403624Наблюдать
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crushftp · crushftp30 авг. 2017 г.
- CVE-2017-1403724Наблюдать
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crushftp · crushftp30 авг. 2017 г.
- CVE-2018-1828824Наблюдать
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crushftp · crushftp25 дек. 2019 г.
- CVE-2024-2291024Наблюдать
Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloa
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crushftp · crushftp14 мая 2024 г.
- CVE-2025-6341924Наблюдать
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.
СредняяCVSS 6,1Proof of conceptEPSS 0 %crushftp · crushftp12 нояб. 2025 г.
- CVE-2025-3210223Наблюдать
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request
СредняяCVSS 5,0Эксплойта нетEPSS 9 %crushftp · crushftp15 апр. 2025 г.
- CVE-2021-4407619Наблюдать
An issue was discovered in CrushFTP 9.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %crushftp · crushftp15 сент. 2022 г.
- CVE-2025-6342016Наблюдать
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pe
СредняяCVSS 4,1Proof of conceptEPSS 0 %crushftp · crushftp7 нояб. 2025 г.