Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-63090 | 8.8 | — | — | — | proftpd / proftpd | ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module tha | 47d ago |
| CVE-2026-35025 | 8.1 | — | — | — | proftpd / proftpd | ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP | 74d ago |
| CVE-2026-53994 | 7.5 | — | — | — | proftpd / proftpd | ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. | 49d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, three catalogues counted; CIRCL shown as an aggregator); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.