Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Splatt ForumAI23/10/200516/6/2026
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
ModificadaAlta (7.5)1.2%💥 ExploitMY Little Homepage MY Little Forum24/9/200516/6/2026
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.
ModificadaAlta (7.5)1.3%—Class-1 Forum SoftwareAI14/9/200516/6/2026
SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file.
ModificadaMedia (5)1.5%—Simple Machines Forum7/9/200516/6/2026
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
ModificadaAlta (7.5)1.9%—Ilia Alshanetsky Fudforum2/9/200516/6/2026
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
ModificadaMedia (5)1.6%—Ilia Alshanetsky Fudforum17/8/200516/6/2026
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
ModificadaAlta (7.5)2.0%—XMB Forum XMB16/8/200516/6/2026
SQL injection vulnerability in u2u.inc.php in XMB Forum 1.9.1 allows remote attackers to execute arbitrary SQL commands via certain values that are inserted into the $in variable.
ModificadaMedia (5)2.1%—XMB Forum XMB16/8/200516/6/2026
xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].
ModificadaMedia (5)1.4%—Beehive ForumAI3/8/200516/6/2026
Beehive Forum permite que atacantes remotos obtengan información confidencial mediante: (1) inválidos parámetros final_uri o sort_by parameter en index.php o una petición directa a: (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8)…
ModificadaAlta (7.5)1.2%—Beehive Forum3/8/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en index.php y otras páginas en Beehive Forum permite que atacantes remotos ejecuten comandos SQL arbitrarios a través del parámetro "webtag"
ModificadaMedia (4.3)1.2%—Beehive Forum3/8/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en index.php en Beehive Forum permite que atacantes remotos inyecten script web o HTML arbitrarios mediante el parámeto "webtag".
ModificadaAlta (7.5)2.7%💥 ExploitClass-1 ForumClever Copy19/7/200516/6/2026
Múltiples vulnerabilidades de inyección de SQL en Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy permiten que atacantes remotos modifiquen sentencias SQL mediante diversos parámetros en "viewattach.php", "users.php" y "viewforum.php".
ModificadaMedia (4.3)1.4%—Class-1 ForumClever Copy19/7/200516/6/2026
Vulnerabilidad de sencuencia de comandos en sitios cruzados en Class-1 Forum 0.24.4 and 0.23.2, y Clever Copy con forums instalados permite que atacantes remotos inyecten script web arbitrario o HTML mediante los parámetros de "users.php" "viewuser_id" o "group".
ModificadaMedia (5)1.2%—BDC Enterprises WEB WIZ Forums12/7/200516/6/2026
Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.
ModificadaMedia (4.3)0.97%—Telligent Systems Community Server Forums5/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaAlta (7.5)2.4%💥 ExploitDuware Duforum22/6/200516/6/2026
Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later…
ModificadaAlta (7.5)1.7%—Gurgens Ultimate Forum18/5/200516/6/2026
Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.
ModificadaMedia (4.3)1.2%—Open Solution Quick.forum14/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.
ModificadaMedia (5)1.4%—Open Solution Quick.forum14/5/200516/6/2026
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
ModificadaMedia (5)1.2%—Battleaxe Software Bttlxeforum14/5/200516/6/2026
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.
ModificadaAlta (7.5)1.3%—Wowbb WEB Forum14/5/200516/6/2026
SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.
ModificadaAlta (7.5)1.3%—Open Solution Quick.forum11/5/200516/6/2026
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
ModificadaMedia (5)1.6%—Myphp Forum3/5/200516/6/2026
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.
ModificadaMedia (5)1.1%—Php-post WEB Forum2/5/200516/6/2026
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
ModificadaMedia (4.3)0.94%—Php-post WEB Forum2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.