Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Mymembersfirst TN Members 1ST Fcu-rdc | 9/9/2014 | 17/6/2026 | The TN Members 1st FCU-RDC (aka com.metova.cuae.tmffcu) application 1.0.28 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Jspautsch Firstlastnames | 23/5/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5.8) | 0.57% | — | Firstdata LinkpointZen-cart ZEN Cart | 4/11/2012 | 16/6/2026 | The LinkPoint module in Zen Cart does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Alta (9.3) | 5.2% | — | Monolith Productions First Encounter Assault Recon | 6/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet… | |
| Analizada | Media (4.3) | 1.0% | — | Opentext FirstclassOpentext Server AND Internet Services | 1/6/2007 | 16/6/2026 | Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | PHP Firstpost | 14/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the Include parameter. | |
| Modificada | Alta (7.1) | 1.8% | — | Mandiant First Response | 20/12/2006 | 16/6/2026 | FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode with SSL enabled, allows remote attackers to cause a denial of service (refused connections) via malformed requests, which results in a mishandled exception. | |
| Modificada | Baja (2.4) | 0.27% | — | Mandiant First Response | 20/12/2006 | 16/6/2026 | FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a denial of service (loss of daemon operation). | |
| Modificada | Baja (2.4) | 0.26% | — | Mandiant First Response | 20/12/2006 | 16/6/2026 | FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a man-in-the-middle (MITM) attack. | |
| Modificada | Alta (9.3) | 6.3% | — | First4internet XCP DRM | 17/11/2005 | 16/6/2026 | The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode. | |
| Modificada | Media (4.6) | 0.40% | — | Sony First4internet XCP Content Management | 3/11/2005 | 16/6/2026 | The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | PHP Firstpost | 3/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Centrinity Firstclass Desktop Client | 2/5/2005 | 16/6/2026 | OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. | |
| Modificada | Alta (7.8) | 2.3% | — | First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate | 31/12/2004 | 16/6/2026 | Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test… | |
| Modificada | Alta (7.8) | 9.2% | 💥 Exploit | Opentext FirstclassAI | 31/12/2004 | 16/6/2026 | The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search. | |
| Modificada | Alta (7.5) | 2.2% | — | Opentext Firstclass Desktop Client | 20/1/2004 | 16/6/2026 | FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Centrinity FirstclassAI | 31/12/2003 | 16/6/2026 | Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory. | |
| Modificada | Media (5) | 2.1% | — | PHP Firstpost | 26/7/2002 | 16/6/2026 | article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message. | |
| Analizada | Media (5) | 1.5% | — | Opentext Firstclass | 22/8/2001 | 16/6/2026 | Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Centrinity Firstclass Intranet Server | 27/6/2000 | 16/6/2026 | FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header. | |
| Modificada | Media (4.6) | 0.33% | — | Softarc Firstclass Internet Server | 30/8/1999 | 16/6/2026 | E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. |