Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.0%—Falconsc WisepointFalconsc Wisepoint Authenticator5/4/201617/6/2026
The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors.
ModificadaMedia (6.8)1.3%—Falconsc Wisepoint5/9/201417/6/2026
Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (4.3)5.3%💥 ExploitHoneywell Falcon Xlweb Linux ControllerHoneywell Falcon Xlweb Xlwebexe24/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.
ModificadaAlta (7.6)3.7%—Honeywell Falcon Xlweb Linux ControllerHoneywell Falcon Xlweb Xlwebexe24/7/201417/6/2026
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.
ModificadaAlta (7.5)6.8%💥 ExploitFalcon Series ONE CMS20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gb_mail, (2) gb_name, and (3) gb_text parameters in a guestbook action to index.php, and unspecified other vectors.
ModificadaMedia (6.8)2.7%💥 ExploitFalcon Series ONE CMS20/12/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the dir[classes] parameter to sitemap.xml.php or (2) the error parameter to errors.php.
ModificadaMedia (4.3)0.88%💥 ExploitFalcon Series ONE CMS20/12/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a password via a certain changepass action to index.php.
ModificadaMedia (4.6)1.2%💥 ExploitFalconseye Project FalconseyeNethackDebian Linux9/6/200316/6/2026
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line option.
ModificadaMedia (4.3)1.5%💥 ExploitBlueface Falcon WEB Server31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
ModificadaAlta (7.5)1.8%—Blueface Falcon WEB Server4/10/200216/6/2026
Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).
ModificadaMedia (5)2.4%—Blueface Falcon WEB Server31/5/200216/6/2026
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.
ModificadaMedia (5)1.9%—Falcon WEB Server28/10/199916/6/2026
Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.
ModificadaMedia (5)1.3%—Blueface Falcon WEB Server26/10/199916/6/2026
Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
Orbitaley — Vulnerabilidades