Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.0% | — | Falconsc WisepointFalconsc Wisepoint Authenticator | 5/4/2016 | 17/6/2026 | The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Falconsc Wisepoint | 5/9/2014 | 17/6/2026 | Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Honeywell Falcon Xlweb Linux ControllerHoneywell Falcon Xlweb Xlwebexe | 24/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input. | |
| Modificada | Alta (7.6) | 3.7% | — | Honeywell Falcon Xlweb Linux ControllerHoneywell Falcon Xlweb Xlwebexe | 24/7/2014 | 17/6/2026 | Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Falcon Series ONE CMS | 20/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Falcon Series ONE CMS | 20/12/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php. | |
| Modificada | Media (4.3) | 0.88% | 💥 Exploit | Falcon Series ONE CMS | 20/12/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | Falconseye Project FalconseyeNethackDebian Linux | 9/6/2003 | 16/6/2026 | Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Blueface Falcon WEB Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages. | |
| Modificada | Alta (7.5) | 1.8% | — | Blueface Falcon WEB Server | 4/10/2002 | 16/6/2026 | Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot). | |
| Modificada | Media (5) | 2.4% | — | Blueface Falcon WEB Server | 31/5/2002 | 16/6/2026 | Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL. | |
| Modificada | Media (5) | 1.9% | — | Falcon WEB Server | 28/10/1999 | 16/6/2026 | Falcon web server allows remote attackers to determine the absolute path of the web root via long file names. | |
| Modificada | Media (5) | 1.3% | — | Blueface Falcon WEB Server | 26/10/1999 | 16/6/2026 | Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |