Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | Wordpress WP Forum | 23/1/2008 | 16/6/2026 | SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Xforum | 15/1/2008 | 16/6/2026 | SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the categorie parameter might also be affected. | |
| Modificada | Media (5.8) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/1/2008 | 16/6/2026 | Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter. | |
| Modificada | Media (5) | 1.2% | — | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb. | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter. | |
| Modificada | Media (6.8) | 0.85% | 💥 Exploit | Myphp Forum | 8/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors. | |
| Modificada | Media (6.8) | 0.96% | 💥 Exploit | Myphp Forum | 4/1/2008 | 16/6/2026 | SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413. | |
| Modificada | Media (4.3) | 1.1% | — | Simpleforum | 3/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in simpleforum.cgi in SimpleForum 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchkey parameter in a search action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Sitescape Forum STSitescape Forum ZX | 21/12/2007 | 16/6/2026 | support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 5/12/2007 | 16/6/2026 | SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Beehive Forum | 5/12/2007 | 16/6/2026 | SQL injection vulnerability in post.php in Beehive Forum 0.7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t_dedupe parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Beehive Forum | 5/12/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Beehive Forum 0.7.1 have unknown "critical" impact and attack vectors, different issues than CVE-2007-6014. | |
| Modificada | Media (5) | 1.1% | — | Simple Machines Forum | 14/11/2007 | 16/6/2026 | Simple Machines Forum (SMF) 1.1.4 allows remote attackers to read a message in private forums by using the advanced search module with the "show results as messages" option, then searching for possible keywords contained in that message. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Invision Power Services Invision Power BoardPhpbbSebflipper Multi-forums Module | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Simple Machines Forum | 23/10/2007 | 16/6/2026 | SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows remote attackers to execute arbitrary SQL commands via the userspec parameter in a search2 action to index.php. | |
| Modificada | Baja (2.6) | 1.0% | — | Simple PHP Forum | 18/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile. | |
| Modificada | Media (5) | 1.2% | — | Quicksilver Forums | 1/10/2007 | 16/6/2026 | Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message. | |
| Modificada | Media (5) | 1.2% | — | Quicksilver Forums | 1/10/2007 | 16/6/2026 | Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Berkeley Boinc Forum | 14/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Boinc Forum 5.10.20 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to forum_forum.php, or the search_string parameter to forum_text_search_action.php in a (2) titles or (3) bodies search. | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Florian Mahieu Dalai Forum | 21/8/2007 | 16/6/2026 | Directory traversal vulnerability in forumreply.php in Dalai Forum 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the chemin parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Aceboard Forum | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in Recherche.php in Aceboard forum allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Auracms Modul Forum Sederhana | 7/8/2007 | 16/6/2026 | SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.4% | — | Phpmyforum | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in editpost.php in phpMyForum before 4.1.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information. |