- Banner
- 220 (vsFTPd 3.0.2)
Raw response
220 (vsFTPd 3.0.2)
Host
Tags: Hosting Self-signed certificate Expired certificate
As of our latest check on 2026-09-25, 121.78.237.19 (KINX, AS9286, South Korea) had 3 open ports (21, 80, 443) and 53 known CVEs, 1 known to be exploited.
Open ports and CVEs as of our latest check of this host, 2026-09-25.
CVEs by severity: CRITICAL 10 HIGH 29 MEDIUM 13 LOW 1
A match is an indication, not proof: it is based on the software version a service reported, and fixes are often backported without changing the version. See the list
Not counted: 82 on a distribution build — the fix may be backported (http_server 2.4.6, openssl 1.0.2k). See them
Not counted: 5 only affect another platform (http_server 2.4.6). See them
Not a Tor relay, not a VPN or privacy relay address, and not on a current public blocklist.
220 (vsFTPd 3.0.2)
HTTP/1.1 302 Found Date: Fri, 25 Sep 2026 04:25:49 GMT Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips Location: https://121.78.237.19/ Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>302 Found</title> </head><body> <h1>Found</h1> <p>The document has moved <a href="https://121.78.237.19/">here</a>.</p> </body></html>
HTTP/1.1 400 Bad Request Date: Fri, 25 Sep 2026 04:25:49 GMT Server: Apache/2.4.6 (CentOS) OpenSSL/1.0.2k-fips Content-Length: 362 Connection: close Content-Type: text/html; charset=iso-8859-1 <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>400 Bad Request</title> </head><body> <h1>Bad Request</h1> <p>Your browser sent a request that this server could not understand.<br /> Reason: You're speaking plain HTTP to an SSL-enabled server port.<br /> Instead use the HTTPS scheme to access this URL, please.<br /> </p> </body></html>
These CVEs were matched on software built by an operating-system distribution whose package revision the service does not show. Distributions often fix a flaw without changing the upstream version number, so whether this build is affected cannot be told from its version. They are not counted. 1 of them is known to be exploited.
CVEs by severity: CRITICAL 15 HIGH 22 MEDIUM 42 LOW 3
| CVE | Software |
|---|---|
| CVE-2021-40438 CRITICAL 9.0 known exploited | http_server 2.4.6 · port 80 |
| CVE-2017-3167 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2017-7679 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2018-1312 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2021-26691 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2021-39275 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2021-44790 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2022-22720 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2022-23943 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2022-31813 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2023-25690 CRITICAL 9.8 | http_server 2.4.6 · port 80 |
| CVE-2017-9788 CRITICAL 9.1 | http_server 2.4.6 · port 80 |
| CVE-2022-22721 CRITICAL 9.1 | http_server 2.4.6 · port 80 |
| CVE-2022-28615 CRITICAL 9.1 | http_server 2.4.6 · port 80 |
| CVE-2022-36760 CRITICAL 9.0 | http_server 2.4.6 · port 80 |
| CVE-2016-5387 HIGH 8.1 | http_server 2.4.6 · port 80 |
| CVE-2017-15715 HIGH 8.1 | http_server 2.4.6 · port 80 |
| CVE-2006-20001 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2016-0736 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2016-2161 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2016-8743 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2017-15710 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2017-9798 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2018-0732 HIGH 7.5 | openssl 1.0.2k · port 80 |
| CVE-2018-1303 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2018-17199 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2019-0217 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2021-23840 HIGH 7.5 | openssl 1.0.2k · port 80 |
| CVE-2021-26690 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2021-34798 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2022-22719 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2022-26377 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2022-29404 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2022-30556 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2023-31122 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2020-35452 HIGH 7.3 | http_server 2.4.6 · port 80 |
| CVE-2023-38709 HIGH 7.3 | http_server 2.4.6 · port 80 |
| CVE-2014-0226 MEDIUM 6.8 | http_server 2.4.6 · port 80 |
| CVE-2017-3736 MEDIUM 6.5 | openssl 1.0.2k · port 80 |
| CVE-2018-0739 MEDIUM 6.5 | openssl 1.0.2k · port 80 |
| CVE-2024-24795 MEDIUM 6.3 | http_server 2.4.6 · port 80 |
| CVE-2016-4975 MEDIUM 6.1 | http_server 2.4.6 · port 80 |
| CVE-2019-10092 MEDIUM 6.1 | http_server 2.4.6 · port 80 |
| CVE-2019-10098 MEDIUM 6.1 | http_server 2.4.6 · port 80 |
| CVE-2020-1927 MEDIUM 6.1 | http_server 2.4.6 · port 80 |
| CVE-2017-3737 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2017-3738 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2018-0734 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2018-0737 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2018-1301 MEDIUM 5.9 | http_server 2.4.6 · port 80 |
| CVE-2018-1302 MEDIUM 5.9 | http_server 2.4.6 · port 80 |
| CVE-2019-1559 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2020-1971 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2021-23841 MEDIUM 5.9 | openssl 1.0.2k · port 80 |
| CVE-2017-3735 MEDIUM 5.3 | openssl 1.0.2k · port 80 |
| CVE-2018-1283 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2019-0220 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2019-1551 MEDIUM 5.3 | openssl 1.0.2k · port 80 |
| CVE-2019-17567 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2020-11985 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2020-1934 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2022-28614 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2022-37436 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2023-3817 MEDIUM 5.3 | openssl 1.0.2k · port 80 |
| CVE-2013-5704 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2013-6438 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2014-0098 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2014-0231 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2014-3581 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2015-0228 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2015-3183 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
| CVE-2018-5407 MEDIUM 4.7 | openssl 1.0.2k · port 80 |
| CVE-2019-1547 MEDIUM 4.7 | openssl 1.0.2k · port 80 |
| CVE-2013-4352 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2014-0117 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2014-0118 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2014-8109 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2015-3185 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2016-8612 MEDIUM 4.3 | http_server 2.4.6 · port 80 |
| CVE-2019-1563 LOW 3.7 | openssl 1.0.2k · port 80 |
| CVE-2020-1968 LOW 3.7 | openssl 1.0.2k · port 80 |
| CVE-2019-1552 LOW 3.3 | openssl 1.0.2k · port 80 |
These CVEs need a platform this host visibly does not run (for example a flaw of the Windows build on a Linux host). They are not counted.
CVEs by severity: HIGH 2 MEDIUM 3
| CVE | Software |
|---|---|
| CVE-2024-40898 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2024-43394 HIGH 7.5 | http_server 2.4.6 · port 80 |
| CVE-2020-13938 MEDIUM 5.5 | http_server 2.4.6 · port 80 |
| CVE-2022-28330 MEDIUM 5.3 | http_server 2.4.6 · port 80 |
| CVE-2014-3523 MEDIUM 5.0 | http_server 2.4.6 · port 80 |
Every port that has answered a connection on this address, and when. A port is listed as open above only when a service was identified on it. Times are UTC.