Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 8/10/2012 | 16/6/2026 | SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter. | |
| Modificada | Media (4.3) | 0.96% | — | Tforum | 31/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in tForum b0.915 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a viewprofile action. | |
| Modificada | Alta (7.5) | 1.2% | — | Tforum | 31/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php. | |
| Modificada | Alta (10) | 2.5% | — | Vbulletin MapiVbulletin ForumVbulletin Suite | 14/8/2012 | 16/6/2026 | Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Asp-dev XM Forums | 25/7/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Beehive Forum | 20/1/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Beehive Forum 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) forum/register.php or (2) forum/logon.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | TOM K Forum Userbar Plugin | 29/11/2011 | 16/6/2026 | SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to execute arbitrary SQL commands via the image2 parameter. | |
| Modificada | Media (4.3) | 0.92% | — | Courseforum Projectforum | 3/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page. | |
| Modificada | Media (4.3) | 0.85% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB FORUM before 5.1 allow remote attackers to inject arbitrary web script or HTML via (1) an e-mail address field or (2) a cookie, a related issue to CVE-2011-3383, CVE-2011-3983, and CVE-2011-3984. | |
| Modificada | Media (4.3) | 2.0% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries." | |
| Modificada | Media (4.3) | 1.7% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies. | |
| Modificada | Media (4.3) | 1.0% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "the web page to be output." | |
| Modificada | Media (5) | 1.2% | — | Vanillaforums Vanilla | 24/9/2011 | 16/6/2026 | Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files. | |
| Modificada | Media (5) | 1.3% | — | Anelectron Advanced Electron Forum | 23/9/2011 | 16/6/2026 | Advanced Electron Forum (AEF) 1.0.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by languages/english/deletetopic_lang.php. | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 24/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 24/8/2011 | 16/6/2026 | SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Vasthtml Forum Server | 21/2/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an… | |
| Modificada | Media (6.4) | 1.0% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks. | |
| Modificada | Media (4.3) | 0.85% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |
| Modificada | Media (5.8) | 0.96% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |
| Modificada | Media (4.3) | 1.3% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action. | |
| Modificada | Media (4.3) | 1.5% | — | Rocomotion P BoardRocomotion P Diary RRocomotion P ForumRocomotion P Link+6 | 20/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Mylittleforum MY Little Forum | 2/6/2010 | 16/6/2026 | SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Nodesforum | 12/4/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to erase_user_data.php and the (2) _nodesforum_code_path parameter to… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Systemsoftware Community Black Forum | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. |