Blueface develops the Falcon web server, a narrowly scoped product with a durable vulnerability signal centered on web-application input handling, particularly cross-site scripting issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Blueface over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2318MEDIUM Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is ins | Dec 31, 2002 | 4.3 | 21 | NO | YES |
CVE-2002-0899HIGH Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot). | Oct 4, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-0275MEDIUM Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL. | May 31, 2002 | 5.0 | 15 | NO | NO |
CVE-1999-0881MEDIUM Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | Oct 26, 1999 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Blueface.
Media articles that mention a CVE ID that affects a product developed by Blueface — matched by CVE ID, not by vendor name.