Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.5%—Simple Machines Forum9/5/200716/6/2026
Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
ModificadaAlta (7.5)1.2%💥 ExploitEsforum25/4/200716/6/2026
SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter.
ModificadaMedia (6.8)4.4%💥 ExploitMaran PHP Forum24/4/200716/6/2026
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter.
ModificadaAlta (7.5)1.5%—MY Little Homepage MY Little Forum18/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php.
ModificadaAlta (7.5)2.8%💥 ExploitForum Picture AND Meta Tags2/4/200716/6/2026
PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaAlta (10)4.2%💥 ExploitEve-nuke Forum30/3/200716/6/2026
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaAlta (7.5)2.8%💥 ExploitTtcms Ttforum27/3/200716/6/2026
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.
ModificadaAlta (7.5)2.9%💥 ExploitGiorgio Ciranni Splatt Forum23/3/200716/6/2026
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is…
ModificadaAlta (7.5)5.5%💥 ExploitMetaforum20/3/200716/6/2026
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php.
ModificadaAlta (7.5)1.8%💥 ExploitWebwizguide WEB WIZ Forums20/3/200716/6/2026
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as…
ModificadaMedia (4.3)1.1%—Snitz Communications Snitz Forums 200010/3/200716/6/2026
Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (10)3.8%—Minibb Forum7/3/200716/6/2026
PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter.
ModificadaAlta (7.5)1.3%💥 ExploitAJ Forum7/3/200716/6/2026
SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter.
ModificadaAlta (7.5)1.1%—Simple PHP Forum2/3/200716/6/2026
Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php.
ModificadaAlta (7.5)2.7%💥 ExploitScripter.ch Sinapis Forum27/2/200716/6/2026
PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter.
ModificadaAlta (7.5)2.4%💥 ExploitTinyphpforum24/2/200716/6/2026
Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter.
ModificadaAlta (7.5)1.1%💥 ExploitSnitz Communications Snitz Forums 200021/2/200716/6/2026
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.4%—Simple Machines Forum15/2/200716/6/2026
QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher…
ModificadaAlta (7.5)1.1%💥 ExploitKisisel Site 2007 Kisisel Site Forum.asp7/2/200716/6/2026
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
ModificadaAlta (7.5)2.5%—RBL Tforum31/1/200716/6/2026
SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp.
ModificadaMedia (6)1.1%—Aztek Forum30/1/200716/6/2026
PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter.
ModificadaAlta (7.5)1.6%—Aztek Forum30/1/200716/6/2026
Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET,…
ModificadaAlta (7.5)1.6%—Aztek Forum30/1/200716/6/2026
common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays.
ModificadaAlta (7.5)1.1%💥 ExploitAztek Forum30/1/200716/6/2026
SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php.
ModificadaAlta (7.5)1.0%💥 ExploitForum Livre30/1/200716/6/2026
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp.
Orbitaley — Vulnerabilidades