Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Zoneo-soft Freeforum | 2/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters. | |
| Modificada | Media (4.3) | 1.8% | — | Simple Machines Forum | 25/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Easy Forum | 24/2/2006 | 16/6/2026 | Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable. | |
| Modificada | Media (4.3) | 2.2% | — | XMB Forum XMB | 19/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag. | |
| Modificada | Alta (7.5) | 3.0% | — | XMB Forum XMB | 19/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Gasoft GAS Forum Light | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's… | |
| Modificada | Alta (7.5) | 1.8% | — | Aspthai.net Aspthai Forums | 1/2/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en login.asp en ASPThai.Net ASPThai Forums 8.0 y versiones anteriores permiten a atacantes remotos ejecutar comandos SQL arbitrarios y eludir la autenticación de inicio de sesión a través del campo de contraseña. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Forum | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 1.8% | — | XMB Software XMB Forum | 22/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element. | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Webwiz WEB WIZ Forums | 11/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Thewebforum | 9/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | ADN Forum | 9/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors. | |
| Modificada | Media (4.3) | 1.4% | — | ADN Forum | 9/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Thewebforum | 9/1/2006 | 16/6/2026 | SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable). | |
| Modificada | Media (4.3) | 1.4% | — | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php. | |
| Modificada | Media (5) | 2.6% | — | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php. | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Vego WEB Forum | 3/1/2006 | 16/6/2026 | SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Pearlinger Pearl Forums | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Pearlinger Pearl Forums | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Oracle Application Server Discussion Forum Portlet | 28/12/2005 | 16/6/2026 | The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00). | |
| Modificada | Media (4.3) | 2.7% | — | Oracle Application Server Discussion Forum Portlet | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1) RowKeyValue parameter in the PORTAL schema; and the (2) title and (3) content input fields when creating an forum article. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Forum ONE Syntaxcms | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Beehive ForumAI | 21/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter. | |
| Modificada | Media (5.1) | 2.1% | 💥 Exploit | Beehive Forum | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php. |