Winscp
17 known vulnerabilities
Top Products
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remot
WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted UR
Buffer overflow in WinSCP 5.17.8 allows a malicious FTP server to cause a denial of service or possibly have other unspe
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filenam
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the s
Frequently Asked Questions
How many CVEs affect Winscp?
Winscp has 17 CVE records in our database, including 2 critical and 7 high severity vulnerabilities.
What are the most severe Winscp vulnerabilities?
Winscp has 2 critical severity (CVSS 9.0+) and 7 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Winscp vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Winscp products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Winscp Vulnerabilities
CyberStrike scans your infrastructure for Winscp vulnerabilities and provides real-time remediation guidance.
Get Started