Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Aceboard Forum | 8/8/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en el Recherche.php del foro Aceboard permite a atacantes remotos ejecutar comandos SQL de su elección a través de vectores sin especificar. | |
| Modificada | Media (5) | 1.3% | — | Dcscripts Dcforumlite | 26/4/2006 | 16/6/2026 | SQL injection vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to execute arbitrary SQL commands via the az parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Dcscripts Dcforumlite | 26/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dcboard.cgi in DCScripts DCForumLite 3.0 allows remote attackers to inject arbitrary web script or HTML via the az parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Dcscripts DcforumDcscripts Dcforum+ | 17/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DCForum 6.25 and earlier, and possibly DCForum+ 1.x, allows remote attackers to inject arbitrary web script or HTML via (1) the page parameter in dcboard.php and (2) unspecified search parameters. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Duware Duforum | 22/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later… | |
| Modificada | Media (4.3) | 0.94% | — | Adalis D-forum | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3. | |
| Modificada | Media (4.3) | 1.9% | — | Duware Duforum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Duware Duforum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Adalis Infomatique D Forum | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3. | |
| Modificada | Alta (7.5) | 1.7% | — | Dcscripts Dcforum | 16/5/2002 | 16/6/2026 | retrieve_password.pl en DCForum 6.x y 2000 genera nuevas contraseñas basadas en un identificador de sesión, lo que permite a atacantes remotos pedir una nueva contraseña aprovechándose de otro usuarios y usar el identificador de sesión para calcular la nueva contraseña de ese usuario. | |
| Modificada | Alta (7.5) | 3.4% | — | Tdavid TD Forum | 31/8/2001 | 16/6/2026 | Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script. | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Dcscripts DcforumDcscripts Dcforum 2000 | 14/8/2001 | 16/6/2026 | DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. | |
| Modificada | Media (5) | 1.7% | — | Dcscripts DcforumDcscripts Dcforum 2000 | 2/7/2001 | 16/6/2026 | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. | |
| Modificada | Alta (7.5) | 2.4% | — | Dcscripts DcforumDcscripts Dcforum 2000 | 2/7/2001 | 16/6/2026 | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | |
| Modificada | Media (6.4) | 9.3% | 💥 Exploit | Dcscripts Dcforum | 9/1/2001 | 16/6/2026 | DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. |