Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | Simple Machines Forum | 9/5/2007 | 16/6/2026 | Session fixation vulnerability in Simple Machines Forum (SMF) 1.1.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Esforum | 25/4/2007 | 16/6/2026 | SQL injection vulnerability in forum.php in EsForum 3.0 allows remote attackers to execute arbitrary SQL commands via the idsalon parameter. | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | Maran PHP Forum | 24/4/2007 | 16/6/2026 | Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | MY Little Homepage MY Little Forum | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Forum Picture AND Meta Tags | 2/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (10) | 4.2% | 💥 Exploit | Eve-nuke Forum | 30/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ttcms Ttforum | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Giorgio Ciranni Splatt Forum | 23/3/2007 | 16/6/2026 | Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is… | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Metaforum | 20/3/2007 | 16/6/2026 | Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type in the Content-type HTTP header, which allows remote attackers to upload and execute arbitrary scripts via an image MIME type with a filename containing an executable extension such as .php. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Webwizguide WEB WIZ Forums | 20/3/2007 | 16/6/2026 | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as… | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (10) | 3.8% | — | Minibb Forum | 7/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in MiniBB Forum 2 allows remote attackers to execute arbitrary code via a URL in the pathToFiles parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | AJ Forum | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in topic_title.php in AJ Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the td_id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Simple PHP Forum | 2/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Scripter.ch Sinapis Forum | 27/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in sinapis.php in Sinapis Forum 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the fuss parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Tinyphpforum | 24/2/2007 | 16/6/2026 | Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 21/2/2007 | 16/6/2026 | SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 15/2/2007 | 16/6/2026 | QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Kisisel Site 2007 Kisisel Site Forum.asp | 7/2/2007 | 16/6/2026 | SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | RBL Tforum | 31/1/2007 | 16/6/2026 | SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp. | |
| Modificada | Media (6) | 1.1% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index/main.php in Aztek Forum 4.00 allows remote authenticated administrators to execute arbitrary PHP code via a URL in the PF[top_url] parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | Variable overwrite vulnerability in common/config.php in Aztek Forum 4.00 allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as copying arbitrary files using index/common_actions.php, via vectors associated with extract operations on the (1) POST, (2) GET,… | |
| Modificada | Alta (7.5) | 1.6% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | common/safety.php in Aztek Forum 4.00 allows remote attackers to enter certain data containing %22 sequences (URL encoded double quotes) and other potentially dangerous manipulations by sending a cookie, which bypasses the blacklist matching against the GET and PUT superglobal arrays. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Aztek Forum | 30/1/2007 | 16/6/2026 | SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL commands via the fid cookie to forum.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Forum Livre | 30/1/2007 | 16/6/2026 | SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to info_user.asp. |