References https://nvd.nist.gov/vuln/detail/CVE-2023-53886 https://www.vulncheck.com/advisories/xlight-ftp-server-stack-buffer-overflow-vulnerability-via-execute-program https://www.exploit-db.com/exploits/51665 https://access.redhat.com/security/cve/cve-2023-53886 https://www.tenable.com/cve/CVE-2023-53886 https://github.com/advisories/GHSA-hxpr-5v98-mw59 https://www.xlightftpd.com/ https://vulnerability.circl.lu/search?vendor=Xlightftpd&product=Xlight+FTP+Server
Related Vulnerabilities畅捷通T+ERP系统SelectBackupFileOnServer接口处存在目录遍历漏洞PoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposureQAnything /api/local_doc_qa/upload_files 文件上传漏洞(CVE-2026-88533)Netbox-Docker /api/status/ 默认口令漏洞(CVE-2023-27573)PoCCVE-2025-11452: Asgaros Forum < 3.2.0 - SQL InjectionPoCCVE-2025-34033: Blue Angel Software Suite (5V Technologies) - OS Command InjectionPoCCVE-2025-62593: Ray < 2.52.0 - Remote Code ExecutionPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information DisclosurePoCCVE-2026-25703: NeuVector - Information DisclosurePoCCVE-2026-61560: GitLab MCP Server < 2.1.27 - Unauthenticated SSE Transport Access