Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.2% | 💥 Exploit | Aspapp Forumapp | 16/2/2009 | 16/6/2026 | ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) data/8690.mdb or (2) data/8690BAK.mdb. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 WEC Discussion Forum | 16/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 WEC Discussion Forum | 16/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Berlios Discussion Forum 2K | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php in misc/; and the (2) SubID parameter to (c) misc/RSS5.php. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Bmforum | 9/2/2009 | 16/6/2026 | SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Adnforum | 28/1/2009 | 16/6/2026 | index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field, and a final :sysop:0 string. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Codeavalanche Freeforum | 21/1/2009 | 16/6/2026 | CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Iyziforum Iyzi Forum | 12/1/2009 | 16/6/2026 | iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Drennansoft MY Simple Forum | 16/12/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter. | |
| Modificada | Media (6.8) | 0.70% | — | Mvnforum | 10/12/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers. | |
| Modificada | Media (4.3) | 1.3% | — | Mvnforum | 10/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | Lovecms THE Simple Forum | 2/12/2008 | 16/6/2026 | The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Tntforum TNT Forum | 28/11/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Forumsoftware Yazd Forum Software | 19/11/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details… | |
| Modificada | Alta (10) | 4.6% | 💥 Exploit | Anelectron Advanced Electron Forum | 14/11/2008 | 16/6/2026 | Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Graphiks Myforum | 12/11/2008 | 16/6/2026 | Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1. | |
| Modificada | Media (4.3) | 1.0% | — | MY Little Forum | 1/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbitrary web script or HTML via BBcode IMG tags. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Easy-script Myforum | 29/10/2008 | 16/6/2026 | Directory traversal vulnerability in admin/centre.php in MyForum 1.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the padmin parameter. | |
| Modificada | Media (6.8) | 0.94% | 💥 Exploit | Graphiks Myforum | 28/10/2008 | 16/6/2026 | SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5.8) | 3.1% | 💥 Exploit | Scripts-for-sites EZ Forum | 27/10/2008 | 16/6/2026 | SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Powie Pforum | 30/9/2008 | 16/6/2026 | SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Novell Forum | 11/9/2008 | 16/6/2026 | Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Alstrasoft Forum PAY PER Post Exchange | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Quicksilver Forums | 12/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Zoneo-soft Freeforum | 10/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely… |