crushftp kayıtları
crushftp üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %17,6
- Silahlaştırılmış
- 4 · %23,5
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %11,8
- Yayından KEV’e ortanca
- 4 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-40 Path Traversal: '\\UNC\share\name\' (Windows UNC Share)1
- CWE-420 Unprotected Alternate Channel1
- CWE-502 Deserialization of Untrusted Data1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2024-4040Silahlaştırılmış | Unauthenticated arbitrary file read and remote code execution in CrushFTPcrushftp · crushftp · CWE-1336 | Kritik10,0 | KEV | %99,5 | 22 Nis 2024 |
99Hemen | CVE-2025-31161Silahlaştırılmış | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instacrushftp · crushftp · CWE-305 | Kritik9,8 | KEV | %100,0 | 3 Nis 2025 |
97Hemen | CVE-2025-54309Silahlaştırılmış | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allowscrushftp · crushftp · CWE-420 | Kritik9,8 | KEV | %94,9 | 18 Tem 2025 |
64Bu hafta | CVE-2023-43177Silahlaştırılmış | CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.crushftp · crushftp · CWE-913 | Kritik9,8 | — | %81,8 | 17 Kas 2023 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,3 | 18 Ara 2023 |
39İzleyin | CVE-2017-14035İstismar yok | CrushFTP 8.x before 8.2.0 has a serialization vulnerability.crushftp · crushftp · CWE-502 | Kritik9,8 | — | %1,6 | 30 Ağu 2017 |
39İzleyin | CVE-2024-53552İstismar yok | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.crushftp · crushftp · CWE-640 | Kritik9,8 | — | %0,8 | 9 Ara 2024 |
25İzleyin | CVE-2025-32103İstismar yok | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files accrushftp · crushftp · CWE-40 | Orta5,0 | — | %18,1 | 15 Nis 2025 |
24İzleyin | CVE-2017-14038İstismar yok | CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.crushftp · crushftp · CWE-601 | Orta6,1 | — | %0,7 | 30 Ağu 2017 |
24İzleyin | CVE-2017-14036İstismar yok | CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.crushftp · crushftp · CWE-79 | Orta6,1 | — | %0,7 | 30 Ağu 2017 |
24İzleyin | CVE-2017-14037İstismar yok | CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.crushftp · crushftp · CWE-93 | Orta6,1 | — | %0,7 | 30 Ağu 2017 |
24İzleyin | CVE-2018-18288İstismar yok | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.crushftp · crushftp · CWE-601 | Orta6,1 | — | %0,6 | 25 Ara 2019 |
24İzleyin | CVE-2024-22910İstismar yok | Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloacrushftp · crushftp · CWE-79 | Orta6,1 | — | %0,5 | 14 May 2024 |
24İzleyin | CVE-2025-63419Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.crushftp · crushftp · CWE-79 | Orta6,1 | — | %0,2 | 12 Kas 2025 |
23İzleyin | CVE-2025-32102İstismar yok | CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request crushftp · crushftp · CWE-918 | Orta5,0 | — | %9,4 | 15 Nis 2025 |
19İzleyin | CVE-2021-44076İstismar yok | An issue was discovered in CrushFTP 9.crushftp · crushftp · CWE-79 | Orta4,8 | — | %0,7 | 15 Eyl 2022 |
16İzleyin | CVE-2025-63420Kavram kanıtı | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pecrushftp · crushftp · CWE-79 | Orta4,1 | — | %0,3 | 7 Kas 2025 |
- CVE-2024-4040100Hemen
Unauthenticated arbitrary file read and remote code execution in CrushFTP
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100crushftp · crushftp22 Nis 2024
- CVE-2025-3116199Hemen
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy insta
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100crushftp · crushftp3 Nis 2025
- CVE-2025-5430997Hemen
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95crushftp · crushftp18 Tem 2025
- CVE-2023-4317764Bu hafta
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
KritikCVSS 9,8SilahlaştırılmışEPSS %82crushftp · crushftp17 Kas 2023
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %93ssh · ssh18 Ara 2023
- CVE-2017-1403539İzleyin
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2crushftp · crushftp30 Ağu 2017
- CVE-2024-5355239İzleyin
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
KritikCVSS 9,8İstismar yokEPSS %1crushftp · crushftp9 Ara 2024
- CVE-2025-3210325İzleyin
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files ac
OrtaCVSS 5,0İstismar yokEPSS %18crushftp · crushftp15 Nis 2025
- CVE-2017-1403824İzleyin
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1crushftp · crushftp30 Ağu 2017
- CVE-2017-1403624İzleyin
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
OrtaCVSS 6,1İstismar yokEPSS %1crushftp · crushftp30 Ağu 2017
- CVE-2017-1403724İzleyin
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1crushftp · crushftp30 Ağu 2017
- CVE-2018-1828824İzleyin
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
OrtaCVSS 6,1İstismar yokEPSS %1crushftp · crushftp25 Ara 2019
- CVE-2024-2291024İzleyin
Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payloa
OrtaCVSS 6,1İstismar yokEPSS %1crushftp · crushftp14 May 2024
- CVE-2025-6341924İzleyin
Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48.
OrtaCVSS 6,1Kavram kanıtıEPSS %0crushftp · crushftp12 Kas 2025
- CVE-2025-3210223İzleyin
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows SSRF via the host and port parameters in a command=telnetSocket request
OrtaCVSS 5,0İstismar yokEPSS %9crushftp · crushftp15 Nis 2025
- CVE-2021-4407619İzleyin
An issue was discovered in CrushFTP 9.
OrtaCVSS 4,8İstismar yokEPSS %1crushftp · crushftp15 Eyl 2022
- CVE-2025-6342016İzleyin
CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling pe
OrtaCVSS 4,1Kavram kanıtıEPSS %0crushftp · crushftp7 Kas 2025