Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 ExploitCodewidgets Threaded Discussion Forum Application31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaMedia (6.8)1.1%💥 ExploitMetyus Forum Portal31/7/200716/6/2026
SQL injection vulnerability in philboard_forum.asp in Metyus Forum Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might be related to CVE-2007-0920 or CVE-2007-3884.
ModificadaAlta (7.5)0.97%💥 ExploitBSM Store Dependent Forums30/7/200716/6/2026
SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp.
ModificadaMedia (4.3)1.0%—Elite Forum25/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter in a ptopic action, a different vulnerability than CVE-2005-3412.
ModificadaMedia (5.8)1.2%—Simple Machines Forum21/7/200716/6/2026
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.1.3 allows remote attackers to include local files via unspecified vectors related to the sourcedir parameter or the actionArray hash. NOTE: CVE and multiple third parties dispute this vulnerability because both sourcedir and actionArray…
ModificadaAlta (7.5)1.9%💥 ExploitAspindir Husrevforum18/7/200716/6/2026
SQL injection vulnerability in philboard_forum.asp in husrevforum 1.0.1 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: it was later reported that 2.0.1 is also affected.
ModificadaMedia (4.3)1.1%—Aspindir Husrevforum18/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in philboard_search.asp in husrevforum 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaBaja (2.6)1.3%—Sitescape Forum17/7/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.
ModificadaMedia (6.4)2.6%💥 ExploitFrank Karau Gl-sh Deaf Forum3/7/200716/6/2026
Multiple directory traversal vulnerabilities in GL-SH Deaf Forum 6.4.4 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) FORUM_LANGUAGE parameter to functions.php or the (2) style parameter to bottom.php.
ModificadaAlta (7.5)4.8%💥 ExploitQt-cute Quicktalk ForumQt-cute Quickticket3/7/200716/6/2026
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) t and (2) f parameters in (a) qti_ind_post.php and (b) qti_ind_post_prt.php; (3) dir and (4) order parameters in qti_ind_member.php; (5) id parameter in…
ModificadaMedia (6.4)7.9%💥 ExploitQt-cute Quicktalk Forum2/7/200716/6/2026
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) sequence in the lang parameter to (1) qtf_checkname.php, (2) qtf_j_birth.php, or (3) qtf_j_exists.php.
ModificadaAlta (10)3.3%—Xeforum29/6/200716/6/2026
Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.
ModificadaMedia (6.8)5.1%💥 ExploitAdam VAN Dongen COM ForumAdam VAN Dongen Phpbb Component26/6/200716/6/2026
PHP remote file inclusion vulnerability in download.php in the Adam van Dongen Forum (com_forum) component (aka phpBB component) 1.2.4RC3 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaAlta (7.5)1.4%—Simple Machines Forum21/6/200716/6/2026
Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.2 allows remote attackers to execute arbitrary PHP code during (1) creation or (2) editing of a message.
ModificadaAlta (7.5)1.4%—Simple Machines Forum21/6/200716/6/2026
Simple Machines Forum (SMF) 1.1.2 uses a concatenation method with insufficient randomization when creating a WAV file CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated brute-force attack.
ModificadaMedia (4.3)1.9%💥 ExploitFuzzylime Forum19/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.
ModificadaMedia (4.3)0.90%💥 ExploitFuzzylime Forum15/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary web script or HTML via the topic parameter. NOTE: this might be resultant from SQL injection.
ModificadaAlta (7.5)1.0%💥 ExploitFuzzylime Forum15/6/200716/6/2026
SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
ModificadaMedia (4.3)1.8%💥 ExploitBeehive Forum14/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.
ModificadaMedia (4.3)1.2%—Sporum Forum14/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in comments.cgi in Sporum Forum 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) mode parameters.
ModificadaMedia (5)1.4%—Rmforum31/5/200716/6/2026
RMForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for rmforum.mdb.
ModificadaAlta (7.5)64%💥 ExploitTroforum31/5/200716/6/2026
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the site_url parameter.
ModificadaAlta (7.5)2.5%💥 ExploitMY Little Homepage MY Little Forum31/5/200716/6/2026
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)2.0%💥 ExploitAgner FOG Aforum13/5/200716/6/2026
PHP remote file inclusion vulnerability in common/errormsg.php in aForum 1.32 and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third…
ModificadaAlta (7.5)3.3%💥 ExploitAgner FOG Aforum11/5/200716/6/2026
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CommonAbsDir parameter.
Orbitaley — Vulnerabilidades