Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | WSN ForumWSN GalleryWSN Knowledge BaseWSN Links | 8/8/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Webwizguide WEB WIZ Forum | 31/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp. | |
| Modificada | Media (5.8) | 0.60% | — | Webwizguide WEB WIZ Forum | 31/7/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Portalparts Forum Plugin | 25/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Easy-script Avlc Forum | 17/7/2008 | 16/6/2026 | SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Marcioforum Mforum | 16/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action. | |
| Modificada | Alta (7.5) | 0.99% | — | Simple Machines Forum | 8/7/2008 | 16/6/2026 | Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Simple Machines Forum | 8/7/2008 | 16/6/2026 | Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors, probably cross-site scripting (XSS), related to "use of the html-tag." | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 WEC Discussion Forum | 7/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Typo3 WEC Discussion Forum | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary code via vectors related to "certain file types." | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | FOG Forum | 3/7/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fog_lang and (2) fog_skin parameters, probably related to libs/required/share.inc; and possibly the (3) fog_pseudo, (4) fog_posted, (5)… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Chaozzatwork Fubarforum | 27/6/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aspindir Meto Forum | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Php-fusion Forum Rank System | 14/5/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown;… | |
| Modificada | Media (4.3) | 1.3% | — | Myvietnam Mvnforum | 9/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows remote authenticated users to inject arbitrary web script or HTML via the topic field, which is later displayed by user/viewthread.jsp through use of the "quick reply button." | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Anelectron Advanced Electron Forum | 27/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Prozilla Forum | 15/4/2008 | 16/6/2026 | SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Jcorporate Eforum | 24/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in busca.php in eForum 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) busca and (2) link parameters. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Qt-cute Quicktalk Forum | 13/3/2008 | 16/6/2026 | SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Gerd Tentler Simple Forum | 1/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Gerd Tentler Simple Forum | 1/2/2008 | 16/6/2026 | Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | WEB WIZ Forums | 29/1/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp. | |
| Modificada | Media (5) | 4.9% | 💥 Exploit | Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a… | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | Alstrasoft Forum PAY PER Post Exchange | 23/1/2008 | 16/6/2026 | AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Alstrasoft Forum PAY PER Post Exchange | 23/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action. |