Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Aztek Forum | 30/1/2007 | 16/6/2026 | Aztek Forum 4.00 allows remote attackers to obtain sensitive information via a direct request to forum.php with the fid=XD query string, which reveals the path in an error message. | |
| Modificada | Media (5.8) | 1.5% | 💥 Exploit | Forum Livre | 30/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web script or HTML via the palavra parameter. | |
| Modificada | Media (5) | 1.5% | — | Telligent Systems Community Server Forums | 29/1/2007 | 16/6/2026 | Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content… | |
| Modificada | Alta (9.4) | 1.7% | — | Zixforum | 29/1/2007 | 16/6/2026 | ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb. NOTE: a followup post suggests that this issue only occurs if the administrator does not properly… | |
| Modificada | Alta (7.5) | 1.4% | — | Zoneo-soft Freeforum | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used | |
| Modificada | Media (6.8) | 1.2% | — | Arnotic A-forum | 22/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum.php3 in Arnaud Guyonne (aka Arnotic) a-forum allow remote attackers to inject arbitrary web script or HTML via the (1) Sujet or (2) Pseudo field. | |
| Modificada | Media (6) | 2.1% | 💥 Exploit | Simple Machines Forum | 22/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Simple Machines Forum (SMF) 1.1 RC3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) recipient or (2) BCC field when selecting send in a pm action. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Uniforum | 13/1/2007 | 16/6/2026 | SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL commands via the "by User" field (aka the TXbyuser parameter). | |
| Modificada | Alta (7.5) | 1.6% | — | 2enetworx Openforum | 5/1/2007 | 16/6/2026 | Openforum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user passwords via a direct request for openforum.mdb. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | VZ Forum | 31/12/2006 | 16/6/2026 | Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrative account name and password hash via a direct request for users/admin.txt. | |
| Modificada | Alta (9.3) | 3.4% | 💥 Exploit | Maxdev Mdforum | 31/12/2006 | 16/6/2026 | Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by… | |
| Modificada | Alta (7.5) | 1.1% | — | Efkan Forum | 31/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.8) | 1.5% | — | Efkan Forum | 31/12/2006 | 16/6/2026 | Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Efkan Forum | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in default.asp in Efkan Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the grup parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Vt-forum Lite | 14/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) StrMsg or (2) Topic_ID parameter to (a) vf_info.asp, (b) vf_newtopic.asp, (c) vf_settings.asp, and (d) vf_replytopic.asp, different vectors than CVE-2006-6447.… | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Vt-forum Lite | 10/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vt-Forum Lite 1.3 and 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the StrMes parameter in vf_info.asp and possibly (2) a URL in the SRC attribute of an IFRAME element that is submitted to vf_newtopic.asp. | |
| Modificada | Alta (7.5) | 1.1% | — | Vt-forum | 10/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vt-Forum Lite 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the user parameter to vf_memberdetail.asp, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.4) | 1.1% | — | Vt-forum Lite | 10/12/2006 | 16/6/2026 | Vt-Forum Lite 1.3 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (10) | 1.8% | — | Kervancilar Aspmforum | 4/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via (1) the soruid parameter in forum2.asp, (2) the ak parameter in kullanicilistesi.asp, (3) the kelimeler parameter in aramayap.asp, and (4) the kullaniciadi parameter in giris.asp; and allow remote… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Basicforum | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Fipsasp Fipsforum | 26/11/2006 | 16/6/2026 | SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Baalasp Forum | 24/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in addpost1.asp in BaalAsp forum allow remote attackers to inject arbitrary web script or HTML via the (1) title (Subject), (2) groupname (Group Name), or (3) detail (Message) field. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Powie Pforum | 22/11/2006 | 16/6/2026 | SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.5% | — | Paul Tarjan Stanford Conference AND Research Forum | 15/11/2006 | 16/6/2026 | generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | THE WEB Drivers Simple Forum | 8/11/2006 | 16/6/2026 | SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attackers to execute arbitrary SQL commands via the id parameter. |