Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Coolforum | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php. | |
| Modificada | Media (5) | 1.2% | — | Forum.pl | 2/5/2005 | 16/6/2026 | The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument. | |
| Modificada | Media (4.3) | 0.94% | — | YET Another Forum.net | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mvnforum | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mvnForum 1.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the Search parameter. | |
| Modificada | Alta (10) | 2.4% | — | Coolforum | 2/5/2005 | 16/6/2026 | CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full… | |
| Modificada | Alta (7.5) | 1.8% | — | Forum.pl | 2/5/2005 | 16/6/2026 | The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | |
| Modificada | Media (4.3) | 1.8% | — | XMB Forum XMB | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XMB Forum 1.9.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Mood or (2) "Send To" fields. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Coolforum | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Adalis D-forum | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3. | |
| Modificada | Alta (7.5) | 1.2% | — | Coolforum | 2/5/2005 | 16/6/2026 | CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Asp-dev XM Forum | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Myphp Forum | 27/4/2005 | 16/6/2026 | Múltiples vulnerabilidades por inyección de SQL en MyPHP Forum 1.0 permiten a atacantes remotos ejecutar comandos SQL de su elección a través de (1) el fid en forum.php, (2)el parámetro 'member' en member.php, (3)el parámetro 'email' en forgot.php, o (4) el parámetro 'nbuser' o el 'nbpass' en include.php. NOTA:… | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | BK DEV BK Forum | 23/4/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Aztek Forum | 7/3/2005 | 16/6/2026 | The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie. | |
| Modificada | Media (4.3) | 1.2% | — | Demof Forumwa | 1/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message. | |
| Modificada | Media (4.3) | 1.2% | — | Forumkit | 13/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Aztek Forum | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Aztek Forum 4.0 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in (a) search.php, (2) the email parameter in (b) subscribe.php, and (3) the return and (4) title parameters in (c) forum_2.php. | |
| Modificada | Media (4.3) | 1.2% | — | Devoybb WEB Forum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (5) | 3.1% | — | XMB Software XMB Forum | 31/12/2004 | 16/6/2026 | Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application. | |
| Modificada | Media (5) | 3.3% | — | XMB Forum XMB | 31/12/2004 | 16/6/2026 | Buffer overflow in Check Point SmartDashboard in Check Point NG AI R54 and R55 allows remote authenticated users to cause a denial of service (server disconnect) and possibly execute arbitrary code via a large filter on a column when using SmartView Tracker. | |
| Modificada | Alta (7.5) | 1.5% | — | Alivesites Forum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter. | |
| Modificada | Alta (7.5) | 4.3% | — | Sunforum | 31/12/2004 | 16/6/2026 | Multiple unspecified vulnerabilities in the H.323 protocol implementation for Sun SunForum 3.2 and 3D 1.0 allow remote attackers to cause a denial of service (segmentation fault and process crash), as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol. | |
| Modificada | Media (4.3) | 0.94% | — | Minihttpserver.net Forum WEB Server | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Wowbb WEB Forum | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65. | |
| Modificada | Media (4.3) | 2.1% | — | XMB Forum XMB | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allow remote attackers to inject arbitrary web script or HTML via (1) the u2uheader parameter in editprofile.php, the restrict parameter in (2) member.php, (3) misc.php, and (4) today.php, and (5) an… |