Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—Zoneo-soft Freeforum2/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.
ModificadaMedia (4.3)1.8%—Simple Machines Forum25/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field.
ModificadaMedia (5)3.1%💥 ExploitEasy Forum24/2/200616/6/2026
Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.
ModificadaMedia (4.3)2.2%—XMB Forum XMB19/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.
ModificadaAlta (7.5)3.0%—XMB Forum XMB19/2/200616/6/2026
Multiple SQL injection vulnerabilities in XMB Forums 1.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) $u2u_select array parameter to u2u.inc.php and (2) $val variable (fidpw0 cookie value) in today.php.
ModificadaAlta (7.5)1.2%💥 ExploitGasoft GAS Forum Light13/2/200616/6/2026
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQL commands via the (1) Forum and (2) pages parameter. NOTE: SecurityTracker says that the vendor has disputed this issue, saying that GA Forum Light does not use an SQL database. SecurityTracker's…
ModificadaAlta (7.5)1.8%—Aspthai.net Aspthai Forums1/2/200616/6/2026
Vulnerabilidad de inyección SQL en login.asp en ASPThai.Net ASPThai Forums 8.0 y versiones anteriores permiten a atacantes remotos ejecutar comandos SQL arbitrarios y eludir la autenticación de inicio de sesión a través del campo de contraseña.
ModificadaMedia (4.3)1.8%—MY Little Homepage MY Little Forum31/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.
ModificadaMedia (4.3)1.8%—XMB Software XMB Forum22/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in XMB (aka extreme message board) allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element.
ModificadaMedia (4.3)3.4%💥 ExploitWebwiz WEB WIZ Forums11/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (4.3)1.8%—Thewebforum9/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in register.php in TheWebForum (twf) 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the www parameter.
ModificadaAlta (7.5)3.2%💥 ExploitADN Forum9/1/200616/6/2026
Multiple SQL injection vulnerabilities in ADN Forum 1.0b allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter in index.php and (2) pagid parameter in verpag.php, and possibly other vectors.
ModificadaMedia (4.3)1.4%—ADN Forum9/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in crear.php in ADN Forum 1.0b allows remote attackers to inject arbitrary web script or HTML via the titulo parameter, which is used by the "Topic name" field.
ModificadaAlta (7.5)2.3%💥 ExploitThewebforum9/1/200616/6/2026
SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).
ModificadaMedia (4.3)1.4%—Ralph Capper Tinyphpforum6/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php.
ModificadaMedia (5)2.6%—Ralph Capper Tinyphpforum6/1/200616/6/2026
Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php.
ModificadaMedia (5)4.1%💥 ExploitRalph Capper Tinyphpforum6/1/200616/6/2026
TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information.
ModificadaAlta (7.5)1.4%—Vego WEB Forum3/1/200616/6/2026
SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.
ModificadaMedia (5)2.6%💥 ExploitPearlinger Pearl Forums31/12/200516/6/2026
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitPearlinger Pearl Forums31/12/200516/6/2026
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)6.1%💥 ExploitOracle Application Server Discussion Forum Portlet28/12/200516/6/2026
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).
ModificadaMedia (4.3)2.7%—Oracle Application Server Discussion Forum Portlet28/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1) RowKeyValue parameter in the PORTAL schema; and the (2) title and (3) content input fields when creating an forum article.
ModificadaMedia (4.3)1.7%💥 ExploitForum ONE Syntaxcms22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
ModificadaAlta (7.5)1.3%💥 ExploitBeehive ForumAI21/12/200516/6/2026
SQL injection vulnerability in index.php in Beehive Forum 0.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_sess parameter.
ModificadaMedia (5.1)2.1%💥 ExploitBeehive Forum21/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Beehive Forum 0.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Description, and (3) Comment fields to (a) links.php and (b) links_add.php.
Orbitaley — Vulnerabilidades