Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

396 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.1%💥 PoCSimple Machines SMF30/4/200816/6/2026
Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated attack that considers Hamming distances. NOTE: this issue reportedly exists because of an…
ModificadaMedia (4.3)1.2%—Simple Machines SMF Shoutbox14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
ModificadaAlta (7.5)3.3%💥 ExploitBoastmachine23/1/200816/6/2026
SQL injection vulnerability in mail.php in boastMachine (aka bMachine) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaBaja (2.6)1.2%💥 ExploitPmachine PRO17/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.
ModificadaMedia (4.3)1.0%—Simple Machines SMF15/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.
ModificadaAlta (7.5)1.2%💥 ExploitMailmachinepro Mailmachine PRO28/12/200716/6/2026
SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 ExploitGetmiro Broadcast Machine14/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in login.php in Miro Project Broadcast Machine 0.9.9.9 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaMedia (5)1.1%—Simple Machines Forum14/11/200716/6/2026
Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message.
ModificadaMedia (6.8)3.0%💥 ExploitSimple Machines Forum23/10/200716/6/2026
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php.
ModificadaMedia (5)3.4%💥 ExploitBoastmachine12/10/200716/6/2026
Directory traversal vulnerability in index.php in boastMachine (aka bMachine) 2.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
ModificadaBaja (2.6)1.4%—SUN Java Virtual Machine11/10/200716/6/2026
Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local…
ModificadaMedia (5.8)1.2%—Simple Machines Forum21/7/200716/6/2026
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray…
ModificadaMedia (5)7.5%💥 ExploitMail Machine11/7/200716/6/2026
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the archives parameter in a Load action.
ModificadaAlta (7.5)1.4%—Simple Machines Forum21/6/200716/6/2026
Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.
ModificadaAlta (7.5)1.4%—Simple Machines Forum21/6/200716/6/2026
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.
ModificadaMedia (4.3)4.5%💥 ExploitBoastmachine31/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in BoastMachine allows remote attackers to inject arbitrary web script or HTML via the blog parameter in a content search action.
ModificadaMedia (6.5)1.1%—Boastmachine24/5/200716/6/2026
user.php in BoastMachine 3.0 platinum allows remote authenticated users to gain privileges via a modified id parameter, as demonstrated by an edit_post action.
ModificadaMedia (6.8)1.5%—Simple Machines Forum9/5/200716/6/2026
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
ModificadaAlta (7.5)9.0%💥 ExploitMAN Machine Systems Jbrowser2/3/200716/6/2026
JBrowser allows remote attackers to bypass authentication and access certain administrative capabilities via a direct request for _admin/.
ModificadaAlta (7.5)1.4%—Simple Machines Forum15/2/200716/6/2026
QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher…
ModificadaMedia (4.9)0.34%—Nomachine NX Server31/1/200716/6/2026
nxconfigure.sh in NoMachine NX Server before 2.1.0-18 does not validate the invoking user, which allows local users to modify server configuration keys in /usr/NX/etc/server.cfg, resulting in an unspecified denial of service.
ModificadaMedia (6)2.1%💥 ExploitSimple Machines Forum22/1/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action.
ModificadaMedia (6.8)1.4%—Simple Machines SMF7/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet Explorer's automatic type…
ModificadaMedia (4.3)1.7%💥 ExploitSimple Machines Forum25/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaMedia (4.3)1.2%—Simple Machines Forum25/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter.
Orbitaley — Vulnerabilidades