Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter. | |
| Modificada | Media (5) | 2.5% | — | Snitz Communications Snitz Forums 2000 | 8/1/2008 | 16/6/2026 | Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb. | |
| Modificada | Alta (7.5) | 1.0% | — | Snitz Communications Snitz Forums 2000 | 5/12/2007 | 16/6/2026 | SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the BuildTime parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Invision Power Services Invision Power BoardPhpbbSebflipper Multi-forums Module | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters. | |
| Modificada | Media (5) | 1.2% | — | Quicksilver Forums | 1/10/2007 | 16/6/2026 | Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message. | |
| Modificada | Media (5) | 1.2% | — | Quicksilver Forums | 1/10/2007 | 16/6/2026 | Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | BSM Store Dependent Forums | 30/7/2007 | 16/6/2026 | SQL injection vulnerability in BSM Store Dependent Forums 1.02 allows remote attackers to execute arbitrary SQL commands via a Username field in an unspecified component, probably the FrmUserName parameter in login.asp. | |
| Modificada | Alta (7.5) | 1.8% | — | Webwizguide WEB WIZ Forums | 20/3/2007 | 16/6/2026 | SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as… | |
| Modificada | Media (4.3) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 10/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pop_profile.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the MSN parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Snitz Communications Snitz Forums 2000 | 21/2/2007 | 16/6/2026 | SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.5% | — | Telligent Systems Community Server Forums | 29/1/2007 | 16/6/2026 | Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content… | |
| Modificada | Alta (7.5) | 3.5% | — | Iprimal Forums | 7/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to execute arbitrary PHP code via a URL in the p parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Iprimal Forums | 7/11/2006 | 16/6/2026 | admin/index.php in IPrimal Forums as of 20061105 allows remote attackers to bypass authentication and modify user passwords via a direct request, possibly related to an authentication issue in admin/chk_admin.php. | |
| Modificada | Alta (7.5) | 1.1% | — | WEB WIZ Forums | 1/11/2006 | 16/6/2026 | SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Snitz Communications Snitz Forums 2000 | 30/10/2006 | 16/6/2026 | SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 7.8% | — | Quicksilver Forums | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter. | |
| Modificada | Media (4.3) | 2.5% | — | Snitz Communications Snitz Forums 2000 | 14/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable). | |
| Modificada | Alta (7.5) | 1.3% | — | Blue Dojo Graffiti Forums | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Snitz Communications Snitz Forums 2000 | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in inc_header.asp in Snitz Forum 3.4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the %strCookieURL%.GROUP parameter in a cookie. | |
| Modificada | Media (6.8) | 1.8% | — | Easy-content Forums | 31/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp. | |
| Modificada | Media (6.4) | 1.1% | — | Easy-content Forums | 31/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp. | |
| Modificada | Media (4.3) | 1.9% | — | Toast Forums | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in toast.asp in Toast Forums 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) author, (2) subject, (3) message, or (4) dayprune parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Dotnetbb Forums | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Aspthai.net Aspthai Forums | 1/2/2006 | 16/6/2026 | SQL injection vulnerability in login.asp in ASPThai.Net ASPThai Forums 8.0 and earlier allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the password field. | |
| Modificada | Media (4.3) | 3.4% | — | Webwiz WEB WIZ Forums | 11/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter. |