Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.3% | — | Comsenz Discuzx | 24/12/2018 | 17/6/2026 | Discuz! DiscuzX 3.4, when WeChat login is enabled, allows remote attackers to bypass authentication by leveraging a non-empty #wechat#common_member_wechatmp to gain login access to an account via a plugin.php ac=wxregister request (the attacker does not have control over which account will be accessed). | |
| Modificada | Media (4.8) | 0.51% | — | Dismall Discuz! | 22/11/2018 | 17/6/2026 | Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code. | |
| Modificada | Media (5.4) | 0.51% | — | Discuzx | 22/4/2018 | 17/6/2026 | Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1_diy_portal_view.tpl.php does not restrict the content. | |
| Modificada | Media (5.4) | 0.51% | — | Discuzx | 22/4/2018 | 17/6/2026 | Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images. | |
| Modificada | Crítica (9.8) | 2.1% | — | Discuzx | 12/1/2018 | 17/6/2026 | Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter. | |
| Modificada | Media (6.1) | 0.83% | — | Discuzx | 12/1/2018 | 17/6/2026 | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter. | |
| Modificada | Media (6.1) | 0.83% | — | Discuzx | 12/1/2018 | 17/6/2026 | Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action. | |
| Modificada | Media (5.4) | 0.64% | — | Discuzx | 10/1/2018 | 17/6/2026 | Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/space_poll.php, as demonstrated by a mod=space do=poll request to home.php. | |
| Modificada | Alta (8.8) | 2.0% | — | Discuzx | 8/1/2018 | 17/6/2026 | Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Discuz Ucenter Home | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action. | |
| Modificada | Media (6.5) | 5.8% | 💥 Exploit | Comsenz Crossday Discuz! Board | 12/8/2009 | 16/6/2026 | wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via the creditsformula parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Discuz! | 12/8/2009 | 16/6/2026 | member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostpasswd and (2) getpasswd actions, possibly involving predictable generation of the id parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Comsenz Discuz | 8/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Discuz GBK | 27/10/2006 | 16/6/2026 | SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie. | |
| Modificada | Alta (7.5) | 2.3% | — | Crosscom Olicom Discuz | 17/8/2005 | 16/6/2026 | Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other multiple extensions that include .php. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Crosscom Olicom Discuz | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary script as other users via an img tag. |