Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 1.0% | — | Opentext FirstclassOpentext Server AND Internet Services | 1/6/2007 | 16/6/2026 | Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.5) | 2.2% | — | Centrinity Firstclass Desktop Client | 2/5/2005 | 16/6/2026 | OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. | |
| Modificada | Alta (7.8) | 9.2% | — | Opentext FirstclassAI | 31/12/2004 | 16/6/2026 | The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search. | |
| Modificada | Alta (7.5) | 2.2% | — | Opentext Firstclass Desktop Client | 20/1/2004 | 16/6/2026 | FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages. | |
| Modificada | Media (5) | 3.4% | — | Centrinity FirstclassAI | 31/12/2003 | 16/6/2026 | Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory. | |
| Analizada | Media (5) | 1.5% | — | Opentext Firstclass | 22/8/2001 | 16/6/2026 | Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | |
| Modificada | Media (5) | 3.1% | — | Centrinity Firstclass Intranet Server | 27/6/2000 | 16/6/2026 | FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header. | |
| Modificada | Media (4.6) | 0.33% | — | Softarc Firstclass Internet Server | 30/8/1999 | 16/6/2026 | E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. |