Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Michelle COX Advanced Forum8/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.1%💥 ExploitDatachecknh ForumpalDatachecknh Forumpal FE8/7/200916/6/2026
SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers to execute arbitrary SQL commands via the (1) password parameter in 1.1 and (2) p_password parameter in 1.5. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.2%💥 ExploitMAX Kervin Kervinet Forum5/7/200916/6/2026
KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10)…
ModificadaAlta (7.5)1.0%💥 ExploitMAX Kervin Kervinet Forum5/7/200916/6/2026
admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitrary accounts and conduct SQL injection attacks via the del_user_id parameter.
ModificadaBaja (3.5)2.5%💥 ExploitMAX Kervin Kervinet Forum5/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.
ModificadaAlta (7.5)0.91%💥 ExploitMAX Kervin Kervinet Forum5/7/200916/6/2026
Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) an enter_parol cookie to index.php in an auto action or (2) the topic parameter to message.php. NOTE: vector 2 can be leveraged for a cross-site scripting (XSS) attack.
ModificadaMedia (4.3)1.3%—XMB Forum XMB5/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in XMB 1.5 allows remote attackers to inject arbitrary web script or HTML via the MSN field during user registration.
ModificadaAlta (7.5)1.1%—MAX Kervin Kervinet Forum5/7/200916/6/2026
SQL injection vulnerability in topic.php in KerviNet Forum 1.1 allows remote attackers to execute arbitrary SQL commands via the forum parameter.
ModificadaAlta (7.5)0.99%💥 ExploitGraphiks Myforum1/6/200916/6/2026
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
ModificadaMedia (6.5)4.0%💥 ExploitKeir Davis X-forum1/5/200916/6/2026
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.
ModificadaAlta (7.5)2.0%💥 ExploitKeir Davis X-forum1/5/200916/6/2026
SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.
ModificadaMedia (5.1)0.88%💥 ExploitMyphp Forum1/5/200916/6/2026
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid…
ModificadaMedia (6.8)4.4%💥 ExploitShopsystem-forum K&S Shopsoftware29/4/200916/6/2026
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/.
ModificadaAlta (7.5)0.97%💥 ExploitSimple Machines Forum21/4/200916/6/2026
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands by setting the db_character_set parameter to a multibyte character set such as big5, which causes the addslashes PHP function to produce a "\" (backslash) sequence that…
ModificadaMedia (5.5)3.3%💥 ExploitSimple Machines Forum7/4/200916/6/2026
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to…
ModificadaMedia (4)2.0%💥 ExploitSimple Machines Forum7/4/200916/6/2026
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package…
ModificadaMedia (6.8)1.1%💥 ExploitSimple Machines Forum7/4/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.
ModificadaAlta (7.5)2.9%💥 ExploitSimple Machines Forum30/3/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and…
ModificadaAlta (7.5)1.1%💥 ExploitGo4i Go41.net ASP Forum25/3/200916/6/2026
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.
ModificadaMedia (5)1.2%—Chaozz Fubarforum24/3/200916/6/2026
FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.
ModificadaAlta (7.5)4.2%💥 ExploitFlysforum Flaber19/3/200916/6/2026
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.
ModificadaAlta (7.5)0.91%💥 ExploitRoman Bogorodskiy Nforum12/3/200916/6/2026
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.
ModificadaMedia (4.3)1.8%💥 ExploitLukas Waldauf Phpfreeforum6/3/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.
ModificadaMedia (4.3)1.8%💥 ExploitBmforum6/3/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to…
ModificadaAlta (7.5)0.97%💥 ExploitCfmsource CF Forum27/2/200916/6/2026
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
Orbitaley — Vulnerabilidades