Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Splatt ForumAI | 23/10/2005 | 16/6/2026 | Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | MY Little Homepage MY Little Forum | 24/9/2005 | 16/6/2026 | SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | |
| Modificada | Alta (7.5) | 1.3% | — | Class-1 Forum SoftwareAI | 14/9/2005 | 16/6/2026 | SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file. | |
| Modificada | Media (5) | 1.5% | — | Simple Machines Forum | 7/9/2005 | 16/6/2026 | Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server. | |
| Modificada | Alta (7.5) | 1.9% | — | Ilia Alshanetsky Fudforum | 2/9/2005 | 16/6/2026 | The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code. | |
| Modificada | Media (5) | 1.6% | — | Ilia Alshanetsky Fudforum | 17/8/2005 | 16/6/2026 | FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | XMB Forum XMB | 16/8/2005 | 16/6/2026 | SQL injection vulnerability in u2u.inc.php in XMB Forum 1.9.1 allows remote attackers to execute arbitrary SQL commands via certain values that are inserted into the $in variable. | |
| Modificada | Media (5) | 2.1% | — | XMB Forum XMB | 16/8/2005 | 16/6/2026 | xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR]. | |
| Modificada | Media (5) | 1.4% | — | Beehive ForumAI | 3/8/2005 | 16/6/2026 | Beehive Forum permite que atacantes remotos obtengan información confidencial mediante: (1) inválidos parámetros final_uri o sort_by parameter en index.php o una petición directa a: (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8)… | |
| Modificada | Alta (7.5) | 1.2% | — | Beehive Forum | 3/8/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en index.php y otras páginas en Beehive Forum permite que atacantes remotos ejecuten comandos SQL arbitrarios a través del parámetro "webtag" | |
| Modificada | Media (4.3) | 1.2% | — | Beehive Forum | 3/8/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en index.php en Beehive Forum permite que atacantes remotos inyecten script web o HTML arbitrarios mediante el parámeto "webtag". | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Class-1 ForumClever Copy | 19/7/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy permiten que atacantes remotos modifiquen sentencias SQL mediante diversos parámetros en "viewattach.php", "users.php" y "viewforum.php". | |
| Modificada | Media (4.3) | 1.4% | — | Class-1 ForumClever Copy | 19/7/2005 | 16/6/2026 | Vulnerabilidad de sencuencia de comandos en sitios cruzados en Class-1 Forum 0.24.4 and 0.23.2, y Clever Copy con forums instalados permite que atacantes remotos inyecten script web arbitrario o HTML mediante los parámetros de "users.php" "viewuser_id" o "group". | |
| Modificada | Media (5) | 1.2% | — | BDC Enterprises WEB WIZ Forums | 12/7/2005 | 16/6/2026 | Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum. | |
| Modificada | Media (4.3) | 0.97% | — | Telligent Systems Community Server Forums | 5/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Duware Duforum | 22/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUforum 3.1, and possibly other versions, allow remote attackers to execute arbitrary SQL commands via the (1) iMsg parameter to messages.asp, iFor parameter to (2) post.asp or (3) forums.asp, or (4) id parameter to userEdit.asp. NOTE: vectors 1 and 3 were later… | |
| Modificada | Alta (7.5) | 1.7% | — | Gurgens Ultimate Forum | 18/5/2005 | 16/6/2026 | Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords. | |
| Modificada | Media (4.3) | 1.2% | — | Open Solution Quick.forum | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action. | |
| Modificada | Media (5) | 1.4% | — | Open Solution Quick.forum | 14/5/2005 | 16/6/2026 | Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files. | |
| Modificada | Media (5) | 1.2% | — | Battleaxe Software Bttlxeforum | 14/5/2005 | 16/6/2026 | forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Wowbb WEB Forum | 14/5/2005 | 16/6/2026 | SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Open Solution Quick.forum | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory. | |
| Modificada | Media (5) | 1.6% | — | Myphp Forum | 3/5/2005 | 16/6/2026 | MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php. | |
| Modificada | Media (5) | 1.1% | — | Php-post WEB Forum | 2/5/2005 | 16/6/2026 | PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters. | |
| Modificada | Media (4.3) | 0.94% | — | Php-post WEB Forum | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |