CrushFTP CrushFTP: known exploited vulnerabilities
Entries3
Ransomware-linked1
First added2024-04-24
Latest2025-07-22
EPSS compared
99.9%
99.5%
95.1%
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2025-54309 | CrushFTP CrushFTP | 2025-07-22 | 95.1% | Unknown |
| CVE-2025-31161 | CrushFTP CrushFTP | 2025-04-07 | 99.9% | Known |
| CVE-2024-4040 | CrushFTP CrushFTP | 2024-04-24 | 99.5% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.