Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.85% | 💥 PoC | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts. | |
| Modificada | Media (4.8) | 0.50% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_category, name. | |
| Modificada | Alta (7.2) | 0.96% | — | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team. | |
| Modificada | Crítica (9.8) | 1.2% | — | Oretnom23 Simple Forum/discussion System | 21/12/2021 | 17/6/2026 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability. | |
| Modificada | Media (5.4) | 0.60% | — | Online Discussion Forum Project Online Discussion Forum | 19/4/2021 | 17/6/2026 | The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page. | |
| Modificada | Crítica (9.8) | 1.2% | — | Guidestar WEC Discussion Forum | 26/11/2019 | 16/6/2026 | The TYPO3 Core wec_discussion extension before 2.1.1 is vulnerable to SQL Injection due to improper sanitation of user-supplied input. | |
| Modificada | Alta (7.5) | 1.2% | — | Webempoweredchurch WEC Discussion | 27/6/2013 | 16/6/2026 | SQL injection vulnerability in the WEC Discussion Forum extension before 2.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Webempoweredchurch WEC Discussion | 19/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in WEC Discussion Forum (wec_discussion) extension 2.1.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in April 2011. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 WEC Discussion Forum | 16/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 WEC Discussion Forum | 16/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Berlios Discussion Forum 2K | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to (a) RSS1.php and (b) RSS2.php in misc/; and the (2) SubID parameter to (c) misc/RSS5.php. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Takempis Discussion WEB | 12/1/2009 | 16/6/2026 | TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for _private/discussion.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | — | Typo3 WEC Discussion Forum | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows attackers to execute arbitrary code via vectors related to "certain file types." | |
| Modificada | Media (4.3) | 1.0% | — | Typo3 WEC Discussion Forum | 7/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the WEC Discussion Forum (wec_discussion) extension 1.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Codewidgets Threaded Discussion Forum Application | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in Message Board / Threaded Discussion Forum Application Template allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.5) | 1.2% | — | Yazd Discussion Forum | 6/11/2006 | 16/6/2026 | Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were… | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Simple Discussion Board | 21/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root parameter to blank.php. | |
| Modificada | Media (4.3) | 1.2% | — | Intelligent Solutions ASP Discussion Forum | 6/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum_search.asp in Intelligent Solutions Inc. ASP Discussion Forum allows remote attackers to inject arbitrary web script or HTML via the search variable. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Aspwebsoft Speedy ASP Discussion Forum | 5/6/2006 | 16/6/2026 | ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Xhawk.net Discussion | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag. | |
| Modificada | Alta (7.5) | 1.3% | — | Xhawk.net Discussion | 19/3/2006 | 16/6/2026 | SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Oracle Application Server Discussion Forum Portlet | 28/12/2005 | 16/6/2026 | The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00). | |
| Modificada | Media (4.3) | 2.7% | — | Oracle Application Server Discussion Forum Portlet | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to inject arbitrary web script or HTML via the (1) RowKeyValue parameter in the PORTAL schema; and the (2) title and (3) content input fields when creating an forum article. |