Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 26% | 💥 Exploit | Invisioncommunity Invision Power BoardInvisionpower Invision Power Board | 31/10/2012 | 16/6/2026 | Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | Scripte24shop Social Network Community | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | 2daybiz Video Community Portal Script | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in index.php in Video Community Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (2.1) | 0.39% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform | 13/8/2012 | 16/6/2026 | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Tbelmans MM Forms Community | 16/6/2012 | 16/6/2026 | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/temp. | |
| Modificada | Media (4) | 1.9% | — | MysqlMysql Community ServerMysql ServerOracle Mysql+1 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Efrontlearning Efront Community ++ | 12/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8)… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | 2daybiz Network Community Script | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Jasperforge Jasperreports Server Community Project | 20/9/2011 | 16/6/2026 | JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach. | |
| Modificada | Media (4.3) | 1.0% | — | Invisioncommunity Invision Power Board | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.2% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Baja (3.5) | 1.3% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | 2daybiz Video Community Portal Script | 28/6/2010 | 16/6/2026 | SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | 2daybiz Video Community Portal Script | 25/6/2010 | 16/6/2026 | SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | 2daybiz Video Community Portal Script | 25/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phpscripte24 WEB Social Network Freunde Community | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Community CMS | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Systemsoftware Community Black Forum | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. | |
| Modificada | Media (5) | 15% | 💥 Exploit | Corejoomla COM Communitypolls | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Media-products Bild Flirt Community | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Invisioncommunity Invision Power Board | 18/11/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to… | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |