Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wing Ftp Server HIGH 7.2
CVE-2026-44403

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authent…

Fix: 8.1.3+
Fix from $1,950 2026-05-12
Wing Ftp Server HIGH 7.8
CVE-2019-25267

Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated…

No fix yet
Fix from $1,950 2026-02-05
Wing Ftp Server HIGH 8.8
CVE-2020-37032

Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authenticated users to execute system c…

No fix yet
Fix from $1,950 2026-01-30
Wing Ftp Server CRITICAL 10.0
CVE-2025-47812 KEVEPSS 95%

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into use…

Fix: 7.4.4+
Fix from $2,300 2025-07-10
Wing Ftp Server HIGH 8.8
CVE-2025-27889

Wing FTP Server before 7.4.4 does not properly validate and sanitize the url parameter of the downloadpass.html endpoint, allowing injection of an ar…

Fix: 7.4.4+
Fix from $1,950 2025-07-10
Wing Ftp Server MEDIUM 6.6
CVE-2025-47811

In Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default. The web app…

Fix: 7.4.4+
Fix from $1,600 2025-07-10
Wing Ftp Server MEDIUM 6.6
CVE-2025-5196

A vulnerability has been found in Wing FTP Server up to 7.4.3 and classified as critical. Affected by this vulnerability is an unknown functionality …

Fix: 7.4.4+
Fix from $1,600 2025-05-26
Wing Ftp Server HIGH 8.8
CVE-2023-37878

Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

Fix: after 7.2.0
Fix from $1,950 2023-09-12
Wing Ftp Server HIGH 8.8
CVE-2023-37881

Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.

Fix: after 7.2.0
Fix from $1,950 2023-09-12
Wing Ftp Server HIGH 7.5
CVE-2023-37879

Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= …

Fix: after 7.2.0
Fix from $1,950 2023-09-12
Wing Ftp Server MEDIUM 5.4
CVE-2023-37875

Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <=…

Fix: after 7.2.0
Fix from $1,600 2023-09-12
Wing Ftp Server MEDIUM 6.1
CVE-2020-27735EPSS 6%

An XSS issue was discovered in Wing FTP 6.4.4. An arbitrary IFRAME element can be included in the help pages via a crafted link, leading to the execu…

No fix yet
Fix from $1,600 2021-01-26
Wing Ftp Server HIGH 7.8
CVE-2020-9470

An issue was discovered in Wing FTP Server 6.2.5 before February 2020. Due to insecure permissions when handling session cookies, a local user may vi…

Fix: after 6.2.5
Fix from $1,950 2020-03-07
Wing Ftp Server HIGH 7.8
CVE-2020-8634

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting…

No fix yet
Fix from $1,950 2020-03-07
Wing Ftp Server HIGH 7.8
CVE-2020-8635

Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files. This allows local…

No fix yet
Fix from $1,950 2020-03-07
Wing Ftp Server MEDIUM 6.8
CVE-2015-4108

Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of adm…

Fix: after 4.4.6
Fix from $1,600 2015-06-10
Wing Ftp Server MEDIUM 6.8
CVE-2012-4729

Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.

Fix: after 4.0.9
Fix from $1,600 2012-10-26
Winftp Ftp Server HIGH 9.0
CVE-2009-0351EPSS 5%

Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument begin…

No fix yet
Fix from $1,950 2009-01-29