Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Crushftp
CRITICAL 9.8
CVE-2025-54309 KEVEPSS 94%
CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote a…
Fix: 10.8.5 / 11.3.4_23+
Fix from $2,300
2025-07-18
Crushftp
CRITICAL 9.8
CVE-2025-31161 KEVEPSS 100%
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is us…
Fix: 10.8.4 / 11.3.1+
Fix from $2,300
2025-04-03
Crushftp
CRITICAL 10.0
CVE-2024-4040 KEVEPSS 100%
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote at…
Fix: 10.7.1 / 11.1.0+
Fix from $2,300
2024-04-22