Web1 vuln-feed

Finding #62

Inventory item apache-test 2.4.37 (software, apache)
TitleCrushFTP CrushFTP: CrushFTP Authentication Bypass Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
Source advisoryCrushFTP CrushFTP: CrushFTP Authentication Bypass Vulnerability
CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Update status