Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%💥 ExploitIprimal Forums7/11/200616/6/2026
admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php.
ModificadaAlta (7.5)3.5%💥 ExploitIprimal Forums7/11/200616/6/2026
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter.
ModificadaMedia (6.5)1.2%—Yazd Discussion Forum6/11/200616/6/2026
Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were…
ModificadaAlta (7.5)1.1%💥 ExploitWEB WIZ Forums1/11/200616/6/2026
SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.
ModificadaCrítica (9.8)1.4%💥 ExploitSnitz Communications Snitz Forums 200030/10/200616/6/2026
SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)2.6%💥 ExploitMinihttp WEB Forum File Sharing Sever Powerpack28/10/200616/6/2026
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.
ModificadaMedia (4.3)1.7%💥 ExploitSimple Machines Forum25/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaMedia (4.3)1.2%—Simple Machines Forum25/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter.
ModificadaAlta (7.5)1.5%—Comdev Forum20/10/200616/6/2026
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)2.9%💥 ExploitWSN Forum20/10/200616/6/2026
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies…
ModificadaAlta (7.5)3.3%💥 ExploitFreeforum11/10/200616/6/2026
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.
ModificadaAlta (7.5)3.3%💥 ExploitForum825/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7)…
ModificadaAlta (7.5)1.5%—Forum ONE Syntaxcms3/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in SyntaxCMS 1.1.1 through 1.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the init_path parameter to admin/testing/tests/0030_init_syntax.php, or (2) an unspecified parameter to admin/testing/index.php. NOTE: the 0004_init_urls.php vector is…
ModificadaAlta (7.5)1.2%💥 ExploitIyzi Forum28/9/200616/6/2026
SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.
ModificadaAlta (7.5)3.5%💥 ExploitForum ONE Syntaxcms28/9/200616/6/2026
PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter.
ModificadaAlta (7.5)7.8%💥 ExploitQuicksilver Forums15/9/200616/6/2026
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.
ModificadaMedia (4.3)2.5%💥 ExploitSnitz Communications Snitz Forums 200014/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).
ModificadaMedia (4.3)1.7%💥 ExploitForumjbc14/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte parameter.
ModificadaMedia (5)1.5%—Muforum7/9/200616/6/2026
muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes.
ModificadaAlta (7.5)1.3%💥 ExploitJohn Andersson Zixforum7/9/200616/6/2026
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter.
ModificadaMedia (5.5)3.3%💥 ExploitTR Forum6/9/200616/6/2026
The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this…
ModificadaAlta (7.5)4.8%💥 ExploitTR Forum6/9/200616/6/2026
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.
ModificadaAlta (9)2.5%—TR Forum6/9/200616/6/2026
SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
ModificadaAlta (7.5)1.8%—Simple Machines Forum31/8/200616/6/2026
Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files,…
ModificadaAlta (7.5)3.8%💥 ExploitXMB Software XMB Forum5/8/200616/6/2026
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.
Orbitaley — Vulnerabilidades