İçeriğe atla
Noroxi

crushftp kayıtları

crushftp üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
3 · %17,6
Silahlaştırılmış
4 · %23,5
Pre-auth RCE
2
Düzeltme kaydı olan
%11,8
Yayından KEV’e ortanca
4 gün

Tüm kayıtlar

17 kayıt
  • Unauthenticated arbitrary file read and remote code execution in CrushFTP

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    crushftp · crushftp22 Nis 2024

  • CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    crushftp · crushftp3 Nis 2025

  • CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95

    crushftp · crushftp18 Tem 2025

  • CVE-2023-43177
    64Bu hafta

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

    KritikCVSS 9,8SilahlaştırılmışEPSS %82

    crushftp · crushftp17 Kas 2023

  • CVE-2023-48795
    51Planlayın

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    OrtaCVSS 5,9Kavram kanıtıEPSS %93

    ssh · ssh18 Ara 2023

  • CVE-2017-14035
    39İzleyin

    CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %2

    crushftp · crushftp30 Ağu 2017

  • CVE-2024-53552
    39İzleyin

    CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

    KritikCVSS 9,8İstismar yokEPSS %1

    crushftp · crushftp9 Ara 2024

  • CVE-2025-32103
    25İzleyin

    CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files ac

    OrtaCVSS 5,0İstismar yokEPSS %18

    crushftp · crushftp15 Nis 2025

  • CVE-2017-14038
    24İzleyin

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %1

    crushftp · crushftp30 Ağu 2017

  • CVE-2017-14036
    24İzleyin

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    crushftp · crushftp30 Ağu 2017

  • CVE-2017-14037
    24İzleyin

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %1

    crushftp · crushftp30 Ağu 2017

  • CVE-2018-18288
    24İzleyin

    CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.

    OrtaCVSS 6,1İstismar yokEPSS %1

    crushftp · crushftp25 Ara 2019

  • CVE-2024-22910
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloa

    OrtaCVSS 6,1İstismar yokEPSS %1

    crushftp · crushftp14 May 2024

  • CVE-2025-63419
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.

    OrtaCVSS 6,1Kavram kanıtıEPSS %0

    crushftp · crushftp12 Kas 2025

  • CVE-2025-32102
    23İzleyin

    CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request

    OrtaCVSS 5,0İstismar yokEPSS %9

    crushftp · crushftp15 Nis 2025

  • CVE-2021-44076
    19İzleyin

    An issue was discovered in CrushFTP 9.

    OrtaCVSS 4,8İstismar yokEPSS %1

    crushftp · crushftp15 Eyl 2022

  • CVE-2025-63420
    16İzleyin

    CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pe

    OrtaCVSS 4,1Kavram kanıtıEPSS %0

    crushftp · crushftp7 Kas 2025