Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | MM Forum Mmforum | 30/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Bfs.kilu Bigforum | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Visialis ABB Forum | 8/3/2010 | 16/6/2026 | Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb. | |
| Modificada | Media (4.3) | 1.1% | — | Todoomasters Todoo Forum | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action. | |
| Modificada | Media (4.3) | 1.0% | — | Frank-karau Phpfk PHP Forum | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Fipsasp Fipsforum | 2/3/2010 | 16/6/2026 | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _database/forumFips.mdb. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Joomla COM Dhforum | 6/1/2010 | 16/6/2026 | SQL injection vulnerability in the DhForum (com_dhforum) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a grouplist action to index.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Maxdev Mdforum | 6/1/2010 | 16/6/2026 | SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 4/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Kunena Forum | 4/1/2010 | 16/6/2026 | SQL injection vulnerability in the Kunena Forum (com_kunena) component 1.5.3 and 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the func parameter to index.php. | |
| Modificada | Media (4.3) | 1.0% | — | Pyforum | 23/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to inject arbitrary web script or HTML via crafted BBcode (1) img or (2) url tags, which are not properly handled when a post is viewed. | |
| Modificada | Media (6.8) | 0.58% | — | Pyforum | 23/12/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to hijack the authentication of victims for requests that change passwords, and other unspecified requests, via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Rocomotion P Forum | 22/12/2009 | 16/6/2026 | Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Fahlstad Wp-forum | 18/12/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the search_max parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to… | |
| Modificada | Media (4.3) | 1.1% | — | Stivaforum Stiva Forum | 16/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Uloki PHP Forum | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | 2enetworx Openforum | 25/8/2009 | 16/6/2026 | OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Quicksilver Forums | 25/8/2009 | 16/6/2026 | Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Yellowswordfish Simple Forum | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Codetoad ASP Forum Script | 3/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Codetoad ASP Forum Script | 3/8/2009 | 16/6/2026 | SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Aspthai.net Aspthai Forums | 23/7/2009 | 16/6/2026 | ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb. | |
| Modificada | Media (4.3) | 1.3% | — | Anelectron Advanced Electron Forum | 20/7/2009 | 16/6/2026 | Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (6.8) | 0.99% | — | Anelectron Advanced Electron Forum | 20/7/2009 | 16/6/2026 | SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.5) | 1.1% | — | Michelle COX Advanced Forum | 8/7/2009 | 16/6/2026 | Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a… |