Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Codewidgets Threaded Discussion Forum Application | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Metyus Forum Portal | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might be related to CVE-2007-0920 or CVE-2007-3884. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | BSM Store Dependent Forums | 30/7/2007 | 16/6/2026 | SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp. | |
| Modificada | Media (4.3) | 1.0% | — | Elite Forum | 25/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vulnerability than CVE-2005-3412. | |
| Modificada | Media (5.8) | 1.2% | — | Simple Machines Forum | 21/7/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray… | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Aspindir Husrevforum | 18/7/2007 | 16/6/2026 | SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected. | |
| Modificada | Media (4.3) | 1.1% | — | Aspindir Husrevforum | 18/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in philboard_search.asp in husrevforum 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.6) | 1.3% | — | Sitescape Forum | 17/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors. | |
| Modificada | Media (6.4) | 2.6% | 💥 Exploit | Frank Karau Gl-sh Deaf Forum | 3/7/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Qt-cute Quicktalk ForumQt-cute Quickticket | 3/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in… | |
| Modificada | Media (6.4) | 7.9% | 💥 Exploit | Qt-cute Quicktalk Forum | 2/7/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php. | |
| Modificada | Alta (10) | 3.3% | — | Xeforum | 29/6/2007 | 16/6/2026 | Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie. | |
| Modificada | Media (6.8) | 5.1% | 💥 Exploit | Adam VAN Dongen COM ForumAdam VAN Dongen Phpbb Component | 26/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 21/6/2007 | 16/6/2026 | Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 21/6/2007 | 16/6/2026 | Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Fuzzylime Forum | 19/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235. | |
| Modificada | Media (4.3) | 0.90% | 💥 Exploit | Fuzzylime Forum | 15/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Fuzzylime Forum | 15/6/2007 | 16/6/2026 | SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Beehive Forum | 14/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460. | |
| Modificada | Media (4.3) | 1.2% | — | Sporum Forum | 14/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters. | |
| Modificada | Media (5) | 1.4% | — | Rmforum | 31/5/2007 | 16/6/2026 | RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Troforum | 31/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | MY Little Homepage MY Little Forum | 31/5/2007 | 16/6/2026 | SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Agner FOG Aforum | 13/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Agner FOG Aforum | 11/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter. |