Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Iprimal Forums | 7/11/2006 | 16/6/2026 | admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Iprimal Forums | 7/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter. | |
| Modificada | Media (6.5) | 1.2% | — | Yazd Discussion Forum | 6/11/2006 | 16/6/2026 | Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | WEB WIZ Forums | 1/11/2006 | 16/6/2026 | SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter. | |
| Modificada | Crítica (9.8) | 1.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 30/10/2006 | 16/6/2026 | SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Minihttp WEB Forum File Sharing Sever Powerpack | 28/10/2006 | 16/6/2026 | join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Simple Machines Forum | 25/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Simple Machines Forum | 25/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) allows remote attackers to inject arbitrary web script or HTML via a base64 encoded params value in the action parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Comdev Forum | 20/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Forum 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | WSN Forum | 20/10/2006 | 16/6/2026 | WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Freeforum | 11/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Forum82 | 5/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7)… | |
| Modificada | Alta (7.5) | 1.5% | — | Forum ONE Syntaxcms | 3/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SyntaxCMS 1.1.1 through 1.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the init_path parameter to admin/testing/tests/0030_init_syntax.php, or (2) an unspecified parameter to admin/testing/index.php. NOTE: the 0004_init_urls.php vector is… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Iyzi Forum | 28/9/2006 | 16/6/2026 | SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Forum ONE Syntaxcms | 28/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Quicksilver Forums | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 14/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable). | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Forumjbc | 14/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte parameter. | |
| Modificada | Media (5) | 1.5% | — | Muforum | 7/9/2006 | 16/6/2026 | muforum (µforum) 0.4c stores membres/members.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | John Andersson Zixforum | 7/9/2006 | 16/6/2026 | SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter. | |
| Modificada | Media (5.5) | 3.3% | 💥 Exploit | TR Forum | 6/9/2006 | 16/6/2026 | The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this… | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | TR Forum | 6/9/2006 | 16/6/2026 | Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php. | |
| Modificada | Alta (9) | 2.5% | — | TR Forum | 6/9/2006 | 16/6/2026 | SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges. | |
| Modificada | Alta (7.5) | 1.8% | — | Simple Machines Forum | 31/8/2006 | 16/6/2026 | Simple Machines Forum (SMF) 1.1RCx before 1.1RC3, and 1.0.x before 1.0.8, does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to perform directory traversal attacks to read arbitrary local files,… | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | XMB Software XMB Forum | 5/8/2006 | 16/6/2026 | SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme. |