Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 329 respecto a la semana anterior
Críticas / altas1265▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | XMB Forum XMB | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to inject arbitrary SQL and gain privileges via the (1) ppp parameter in viewthread.php, (2) desc parameter in misc.php, (3) tpp parameter in forumdisplay.php, (4) ascdesc parameter in forumdisplay.php, or (5) the addon parameter in… | |
| Modificada | Media (4.3) | 0.99% | — | Wowbb WEB Forum | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Duware Duforum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands via the FOR_ID parameter in messages.asp, (2) MSG_ID parameter in messageDetail.asp, or (3) password parameter in the login form. | |
| Modificada | Media (5.8) | 1.5% | — | Webwiz WEB WIZ Forums | 31/12/2004 | 16/6/2026 | Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topics via pop_up_topic_admin.asp. | |
| Modificada | Media (4.3) | 1.9% | — | Duware Duforum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Devoybb WEB Forum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Aborior Encore WEB Forum | 31/12/2004 | 16/6/2026 | display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable. | |
| Modificada | Media (4.6) | 0.31% | — | Minihttpserver.net WEB Forums ServerAI | 31/12/2004 | 16/6/2026 | Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.4% | — | Alivesites Forum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp. | |
| Modificada | Media (5) | 1.5% | — | Minihttpserver.net WEB Forums Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash). | |
| Modificada | Media (5) | 2.7% | — | Yabbforumsoftware YET Another Bulletin Board | 23/11/2004 | 16/6/2026 | YaBB SP 1.3.1 muestra mensajes de erro diferentes cuando un usuario existe o no, lo que hace más fácil para atacantes remotos identificar usuarios válidos y llevar a cabo ataques de adivinación de contraseñas por fuerza bruta. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 16/9/2004 | 16/6/2026 | CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter. | |
| Modificada | Media (6.8) | 2.4% | — | Powie Pforum | 16/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile. | |
| Modificada | Media (4.3) | 2.5% | — | XMB Forum XMB | 26/3/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Extreme Messageboard (XMB) 1.8 SP3 and 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) xmbuser parameter to xmb.php, (2) folder parameter to u2u.php, (3) viewmost, replymost, or latest parameter to stats.php, (4) message or icons… | |
| Modificada | Alta (7.5) | 2.2% | — | XMB Forum XMB | 26/3/2004 | 16/6/2026 | SQL injection vulnerability in Extreme Messageboard (XMB) 1.9 beta allows remote attackers to execute arbitrary SQL commands via the restrict parameter to (1) member.php, (2) misc.php, or (3) today.php. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | XMB Forum XMB | 23/2/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php, (2) uid parameter in u2uadmin.php, (3) user parameter in editprofile.php, (4) an onmouseover event in an align tag when bbcode is… | |
| Modificada | Media (4.3) | 1.2% | — | Intra Forum | 24/1/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | TtcmsTtcms Ttforum | 31/12/2003 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Kelli Shaver S8forum | 31/12/2003 | 16/6/2026 | register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)"… | |
| Modificada | Alta (7.5) | 1.1% | — | TtcmsTtcms Ttforum | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name. | |
| Modificada | Media (5) | 1.1% | — | Petitforum | 31/12/2003 | 16/6/2026 | Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Adalis Infomatique D Forum | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3. | |
| Modificada | Media (6.4) | 7.2% | 💥 Exploit | BDC Enterprises WEB WIZ Forums | 31/12/2003 | 16/6/2026 | post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or write to private forums by modifying the FID (forum ID) parameter. |