Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.1% | 💥 PoC | Simple Machines SMF | 30/4/2008 | 16/6/2026 | Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated attack that considers Hamming distances. NOTE: this issue reportedly exists because of an… | |
| Modificada | Media (4.3) | 1.2% | — | Simple Machines SMF Shoutbox | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";". | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Boastmachine | 23/1/2008 | 16/6/2026 | SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (2.6) | 1.2% | 💥 Exploit | Pmachine PRO | 17/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Simple Machines SMF | 15/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mailmachinepro Mailmachine PRO | 28/12/2007 | 16/6/2026 | SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Getmiro Broadcast Machine | 14/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in Miro Project Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5) | 1.1% | — | Simple Machines Forum | 14/11/2007 | 16/6/2026 | Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Simple Machines Forum | 23/10/2007 | 16/6/2026 | SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Boastmachine | 12/10/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. | |
| Modificada | Baja (2.6) | 1.4% | — | SUN Java Virtual Machine | 11/10/2007 | 16/6/2026 | Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local… | |
| Modificada | Media (5.8) | 1.2% | — | Simple Machines Forum | 21/7/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray… | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Mail Machine | 11/7/2007 | 16/6/2026 | Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 21/6/2007 | 16/6/2026 | Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 21/6/2007 | 16/6/2026 | Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Boastmachine | 31/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action. | |
| Modificada | Media (6.5) | 1.1% | — | Boastmachine | 24/5/2007 | 16/6/2026 | user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action. | |
| Modificada | Media (6.8) | 1.5% | — | Simple Machines Forum | 9/5/2007 | 16/6/2026 | Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | MAN Machine Systems Jbrowser | 2/3/2007 | 16/6/2026 | JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 15/2/2007 | 16/6/2026 | QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher… | |
| Modificada | Media (4.9) | 0.34% | — | Nomachine NX Server | 31/1/2007 | 16/6/2026 | nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service. | |
| Modificada | Media (6) | 2.1% | 💥 Exploit | Simple Machines Forum | 22/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action. | |
| Modificada | Media (6.8) | 1.4% | — | Simple Machines SMF | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet Explorer's automatic type… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Simple Machines Forum | 25/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Simple Machines Forum | 25/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter. |