VendorsCore FTPcore_ftp2.0
Vulnerabilities

Core FTP Core FTP 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2019-25686
Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service
Published 2026-04-05 · Analyzed
8.7EPSS 0.005
CVE-2018-20658
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.
Published 2019-01-02 · Modified
7.51 PoCEPSS 0.085
CVE-2020-19595
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
Published 2021-04-05 · Modified
7.5EPSS 0.011
CVE-2022-22836
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.
Published 2022-01-08 · Modified
6.51 PoCEPSS 0.054
CVE-2022-22899
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
Published 2022-02-17 · Modified
5.5EPSS 0.009
CVE-2019-9649
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.
Published 2019-03-22 · Modified
5.31 PoCEPSS 0.145
CVE-2019-9648
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the returned information.
Published 2019-03-22 · Modified
5.31 PoCEPSS 0.143