Vulnerabilities (CVE)

Filtered by vendor Winscp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3331 1 Winscp 1 Winscp 2021-02-04 10.0 HIGH 9.8 CRITICAL
WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)
CVE-2020-28864 1 Winscp 1 Winscp 2020-12-02 7.5 HIGH 9.8 CRITICAL
Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspecified impact via a long file name.