Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.9%💥 ExploitWSN ForumWSN GalleryWSN Knowledge BaseWSN Links8/8/200816/6/2026
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot…
ModificadaMedia (4.3)1.5%💥 ExploitWebwizguide WEB WIZ Forum31/7/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.
ModificadaMedia (5.8)0.60%—Webwizguide WEB WIZ Forum31/7/200816/6/2026
Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp.
ModificadaMedia (4.3)1.2%—Portalparts Forum Plugin25/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.
ModificadaAlta (7.5)0.97%💥 ExploitEasy-script Avlc Forum17/7/200816/6/2026
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.
ModificadaMedia (6.8)1.1%💥 ExploitMarcioforum Mforum16/7/200816/6/2026
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action.
ModificadaAlta (7.5)0.99%—Simple Machines Forum8/7/200816/6/2026
Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.
ModificadaAlta (7.5)1.1%—Simple Machines Forum8/7/200816/6/2026
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors, probably cross-site scripting (XSS), related to "use of the html-tag."
ModificadaMedia (4.3)1.0%—Typo3 WEC Discussion Forum7/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.0%—Typo3 WEC Discussion Forum7/7/200816/6/2026
Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary code via vectors related to "certain file types."
ModificadaAlta (7.5)2.4%💥 ExploitFOG Forum3/7/200816/6/2026
Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) fog_lang and (2) fog_skin parameters, probably related to libs/required/share.inc; and possibly the (3) fog_pseudo, (4) fog_posted, (5)…
ModificadaMedia (6.8)1.9%💥 ExploitChaozzatwork Fubarforum27/6/200816/6/2026
Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaAlta (7.5)2.3%💥 ExploitAspindir Meto Forum27/5/200816/6/2026
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) admin/duzenle.asp and (b) admin_oku.asp; the (2) kid parameter to (c) kategori.asp and (d) admin_kategori.asp; and unspecified parameters to (e) uye.asp and (f) oku.asp.
ModificadaMedia (6.8)1.9%💥 ExploitPhp-fusion Forum Rank System14/5/200816/6/2026
Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown;…
ModificadaMedia (4.3)1.3%—Myvietnam Mvnforum9/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows remote authenticated users to inject arbitrary web script or HTML via the topic field, which is later displayed by user/viewthread.jsp through use of the "quick reply button."
ModificadaMedia (4.3)1.5%💥 ExploitAnelectron Advanced Electron Forum27/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.
ModificadaMedia (6.8)0.91%💥 ExploitProzilla Forum15/4/200816/6/2026
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
ModificadaMedia (4.3)1.1%—Jcorporate Eforum24/3/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in busca.php in eForum 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) busca and (2) link parameters.
ModificadaMedia (6.8)0.91%💥 ExploitQt-cute Quicktalk Forum13/3/200816/6/2026
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.4%💥 ExploitGerd Tentler Simple Forum1/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.
ModificadaMedia (5)2.7%💥 ExploitGerd Tentler Simple Forum1/2/200816/6/2026
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
ModificadaMedia (5)3.9%💥 ExploitWEB WIZ Forums29/1/200816/6/2026
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.
ModificadaMedia (5)4.9%💥 ExploitWebwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor29/1/200816/6/2026
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a…
ModificadaMedia (5)2.1%💥 ExploitAlstrasoft Forum PAY PER Post Exchange23/1/200816/6/2026
AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access user accounts.
ModificadaAlta (7.5)1.2%💥 ExploitAlstrasoft Forum PAY PER Post Exchange23/1/200816/6/2026
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.
Orbitaley — Vulnerabilidades