Vulnerabilities
28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-55055 | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2022-46368 | Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users. Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2020-27575 | Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to command injection due to insufficient validation. NVD description · AI analysis pending | 8.8 group max | 3% | PoC |
| — | |
| CVE-2020-12737 | An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2019-19664 | A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html. NVD description · AI analysis pending | 7.1 group max | <1% |
| — | ||
| CVE-2019-19659 | A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2020-8514 | An issue was discovered in Rumpus 8.2.10 on macOS. An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-19368 | A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts NVD description · AI analysis pending | 6.1 | 26% | PoC ×2 |
| — |