Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Advanced Forum Signatures Project Advanced Forum Signatures | 8/4/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4 for MyBB allow remote attackers to execute arbitrary SQL commands via the (1) afs_type, (2) afs_background, (3) afs_showonline, (4) afs_bar_left, (5) afs_bar_center, (6) afs_full_line1, (7)… | |
| Modificada | Media (5) | 3.3% | — | Zingiri Forums | 4/4/2014 | 16/6/2026 | Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php. | |
| Modificada | Alta (7.5) | 2.2% | — | Cartpauj Mingle-forum | 2/4/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php. | |
| Modificada | Media (4.3) | 2.1% | — | Cartpauj Mingle-forum | 28/3/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to… | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action. | |
| Modificada | Media (4.3) | 2.0% | — | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action. | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Jforum | 30/12/2013 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requests that change the user group permissions of arbitrary users via a groupsSave action. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Mybb Ajax Forum Stat | 4/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter. | |
| Modificada | Media (4.6) | 2.4% | — | Simplemachines Simple Machines Forum | 25/10/2013 | 16/6/2026 | Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. | |
| Modificada | Media (6.8) | 1.1% | — | Cartpauj Mingle-forum | 9/10/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) modify user privileges or (2) conduct cross-site scripting (XSS) attacks via unspecified vectors. | |
| Modificada | Media (5.8) | 1.1% | — | Jforum | 23/9/2013 | 16/6/2026 | Open redirect vulnerability in JForum 2.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnPath parameter in a validateLogin action to jforum.page. | |
| Modificada | Baja (2.6) | 1.2% | — | FudforumIlia Alshanetsky Fudforum | 16/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Vanillaforums Latestcomment | 23/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Wesley Destailleur Todoo Forum | 13/5/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Wesley Destailleur Todoo Forum | 13/5/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter. | |
| Modificada | Alta (7.5) | 5.7% | 💥 Exploit | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection." | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Jforum | 24/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in jforum.page in JForum 2.1.9 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) match_type, (3) sort_by, or (4) start parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Wikidforum | 24/1/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search_select parameters. NOTE: this issue could not be reproduced by third parties. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Wikidforum | 24/1/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or (3) select_sort parameters in an advanced search. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Ramui Forum | 27/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Baja (3.5) | 1.1% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 15/11/2012 | 16/6/2026 | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue. | |
| Modificada | Media (6.5) | 1.5% | — | Cartpauj Mingle-forum | 8/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress might allow remote authenticated users to execute arbitrary SQL commands via the (1) memberid or (2) groupid parameters in a removemember action or (3) id parameter to fs-admin/fs-admin.php, or (4)… | |
| Modificada | Media (6.5) | 1.7% | — | Cartpauj Mingle-forum | 8/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in fs-admin/fs-admin.php in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) delete_usrgrp[] parameter in a delete_usergroups action, (2) usergroup parameter in an… |