Known Vulnerabilities for Sftp/scp Server by Solarwinds
Listed below are 2 of the newest known vulnerabilities associated with "Sftp/scp Server" by "Solarwinds".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59995 json | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used w... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-59848 json | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queue... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-59844 json | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, c... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-53422 json | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enume... | Not Provided | 2026-07-02 | 2026-07-03 |
| CVE-2026-50203 json | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or comp... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-49297 json | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-49238 json | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), whi... | Not Provided | 2026-05-28 | 2026-05-28 |
| CVE-2026-49129 json | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin wher... | Not Provided | 2026-05-28 | 2026-07-14 |
| CVE-2026-45695 json | Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end enc... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2026-43943 json | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code exec... | Not Provided | 2026-05-08 | 2026-05-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Solarwinds | Sftp/scp Server | 2018-09-10 | |||
| Application | Solarwinds | Sftp/scp Server | - |