Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Michelle COX Advanced Forum | 8/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Datachecknh ForumpalDatachecknh Forumpal FE | 8/7/2009 | 16/6/2026 | SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | MAX Kervin Kervinet Forum | 5/7/2009 | 16/6/2026 | KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10)… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | MAX Kervin Kervinet Forum | 5/7/2009 | 16/6/2026 | admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter. | |
| Modificada | Baja (3.5) | 2.5% | 💥 Exploit | MAX Kervin Kervinet Forum | 5/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | MAX Kervin Kervinet Forum | 5/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack. | |
| Modificada | Media (4.3) | 1.3% | — | XMB Forum XMB | 5/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in XMB 1.5 allows remote attackers to inject arbitrary web script or HTML via the MSN field during user registration. | |
| Modificada | Alta (7.5) | 1.1% | — | MAX Kervin Kervinet Forum | 5/7/2009 | 16/6/2026 | SQL injection vulnerability in topic.php in KerviNet Forum 1.1 allows remote attackers to execute arbitrary SQL commands via the forum parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Graphiks Myforum | 1/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |
| Modificada | Media (6.5) | 4.0% | 💥 Exploit | Keir Davis X-forum | 1/5/2009 | 16/6/2026 | Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Keir Davis X-forum | 1/5/2009 | 16/6/2026 | SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php. | |
| Modificada | Media (5.1) | 0.88% | 💥 Exploit | Myphp Forum | 1/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid… | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | Shopsystem-forum K&S Shopsoftware | 29/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Simple Machines Forum | 21/4/2009 | 16/6/2026 | SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that… | |
| Modificada | Media (5.5) | 3.3% | 💥 Exploit | Simple Machines Forum | 7/4/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to… | |
| Modificada | Media (4) | 2.0% | 💥 Exploit | Simple Machines Forum | 7/4/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Simple Machines Forum | 7/4/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Simple Machines Forum | 30/3/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Go4i Go41.net ASP Forum | 25/3/2009 | 16/6/2026 | SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter. | |
| Modificada | Media (5) | 1.2% | — | Chaozz Fubarforum | 24/3/2009 | 16/6/2026 | FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Flysforum Flaber | 19/3/2009 | 16/6/2026 | function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Roman Bogorodskiy Nforum | 12/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Lukas Waldauf Phpfreeforum | 6/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Bmforum | 6/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Cfmsource CF Forum | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter. |