WinSCP is a widely deployed file-transfer client that handles SSH and SFTP operations across diverse enterprise and individual user environments, presenting a notable attack surface due to its direct exposure to user input and file-system operations. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and recur through weakness classes including improper input validation, buffer overflows, path traversal, and argument injection—issues characteristic of applications that parse remote protocols and construct file paths or system commands. Defenders should treat WinSCP advisories as high-priority given the client's role in privileged file access and the availability of weaponizable exploits; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winscp over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1359HIGH Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary | Dec 23, 2002 | 10.0 | 85 | NO | YES |
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2019-6111MEDIUM An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the s | Jan 31, 2019 | 5.9 | 67 | NO | YES |
CVE-2019-6110MEDIUM In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for ex | Jan 31, 2019 | 6.8 | 44 | NO | YES |
CVE-2002-1357HIGH Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or | Dec 23, 2002 | 10.0 | 35 | NO | NO |
CVE-2007-4909HIGH Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a | Sep 17, 2007 | 9.3 | 34 | NO | YES |
CVE-2021-3331CRITICAL WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploit | Jan 27, 2021 | 9.8 | 33 | NO | NO |
CVE-2002-1358HIGH Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arb | Dec 23, 2002 | 10.0 | 33 | NO | NO |
CVE-2006-3015HIGH Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or | Jun 14, 2006 | 7.1 | 29 | NO | YES |
CVE-2002-1360HIGH Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attack | Dec 23, 2002 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winscp.
Media articles that mention a CVE ID that affects a product developed by Winscp — matched by CVE ID, not by vendor name.