Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Androidforums Forum FOR Android | 15/9/2014 | 17/6/2026 | The Android Forums (aka com.tapatalk.androidforumscom) application 2.4.4.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 3.3% | — | Zingiri Forums | 4/4/2014 | 16/6/2026 | Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php. | |
| Modificada | Media (4.3) | 2.1% | — | Vanillaforums Latestcomment | 23/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | |
| Modificada | Alta (7.5) | 5.7% | — | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection." | |
| Modificada | Alta (7.5) | 3.5% | — | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest. | |
| Modificada | Baja (3.5) | 1.1% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 15/11/2012 | 16/6/2026 | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue. | |
| Modificada | Alta (7.5) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 8/10/2012 | 16/6/2026 | SQL injection vulnerability in forum.asp in Snitz Forums 2000 allows remote attackers to execute arbitrary SQL commands via the TOPIC_ID parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Asp-dev XM Forums | 25/7/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASP-DEv XM Forums RC3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) profile.asp, (2) forum.asp, or (3) topic.asp. | |
| Modificada | Media (5) | 1.2% | — | Vanillaforums Vanilla | 24/9/2011 | 16/6/2026 | Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files. | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 24/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to inject arbitrary web script or HTML via the M_NAME parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 24/8/2011 | 16/6/2026 | SQL injection vulnerability in members.asp in Snitz Forums 2000 3.4.07 allows remote attackers to execute arbitrary SQL commands via the M_NAME parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.4) | 1.0% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks. | |
| Modificada | Media (4.3) | 0.85% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |
| Modificada | Media (5.8) | 0.96% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |
| Modificada | Media (4.3) | 1.3% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action. | |
| Modificada | Media (4.3) | 1.8% | — | Snitz Communications Snitz Forums 2000 | 4/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag. | |
| Modificada | Alta (7.5) | 3.2% | — | Quicksilver Forums | 25/8/2009 | 16/6/2026 | Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a… | |
| Modificada | Media (5) | 5.9% | — | Aspthai.net Aspthai Forums | 23/7/2009 | 16/6/2026 | ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb. | |
| Modificada | Media (4.3) | 1.0% | — | Forumsoftware Yazd Forum Software | 19/11/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details… | |
| Modificada | Alta (7.5) | 1.0% | — | Quicksilver Forums | 12/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL commands via the forums array parameter in a search action. | |
| Modificada | Media (5) | 3.9% | — | WEB WIZ Forums | 29/1/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp. | |
| Modificada | Media (5) | 4.9% | — | Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a… | |
| Modificada | Media (5.8) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/1/2008 | 16/6/2026 | Open redirect vulnerability in Forums/login.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to redirect users to arbitrary web sites via a URL in the target parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Snitz Forums 2000 3.4.05 and earlier allows remote attackers to inject arbitrary web script or HTML via the target parameter. | |
| Modificada | Media (5) | 1.2% | — | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path. |