Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Teekai Forum | 31/12/2002 | 16/6/2026 | TeeKai Forum 1.2 allows remote attackers to authenticate as the administrator and and gain privileged web forum access by setting the valid_level cookie to admin. | |
| Modificada | Media (5) | 1.5% | — | Wwwebbb Forum | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in page.cgi of WWWeBBB Forum 3.82 beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Splatt Forum | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script. | |
| Modificada | Media (5.1) | 1.3% | — | Zeroforum | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Powie Pforum | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | XMB Software XMB Forum | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 18/6/2002 | 16/6/2026 | members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL. | |
| Modificada | Alta (10) | 2.4% | — | Powie Pforum | 31/5/2002 | 16/6/2026 | pforum 1.14 y anteriores no habilita explícitamente las comillas mágicas (magic quotes) PHP quotes, lo que permite a atacantes remotos evitar la autenticación y ganar privilegios de administrador mediante un ataque de inyección de SQL cuando el servidor no está configurado para usar las comillas mágicas. | |
| Modificada | Alta (7.5) | 1.7% | — | Dcscripts Dcforum | 16/5/2002 | 16/6/2026 | retrieve_password.pl en DCForum 6.x y 2000 genera nuevas contraseñas basadas en un identificador de sesión, lo que permite a atacantes remotos pedir una nueva contraseña aprovechándose de otro usuarios y usar el identificador de sesión para calcular la nueva contraseña de ese usuario. | |
| Modificada | Alta (7.5) | 3.3% | — | Allaire Forums | 25/3/2002 | 16/6/2026 | Allaire Forums 2.0.4 y 2.0.5 y Foros! 3.0 y 3.1 permiten a usuarios remotos autorizados suplantar la identidad de otros usuarios (Spoofing) para enviar mensajes modificando en el formulario los campos de nombre y dirección de correo. | |
| Modificada | Alta (7.5) | 3.4% | — | Tdavid TD Forum | 31/8/2001 | 16/6/2026 | Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script. | |
| Modificada | Alta (10) | 3.8% | — | Surf-net ASP Forum | 31/8/2001 | 16/6/2026 | Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888." | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Dcscripts DcforumDcscripts Dcforum 2000 | 14/8/2001 | 16/6/2026 | DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symbols (|) and newlines into the last name in the registration form, which will create an extra entry in the registration database. | |
| Modificada | Media (5) | 1.7% | — | Dcscripts DcforumDcscripts Dcforum 2000 | 2/7/2001 | 16/6/2026 | upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file. | |
| Modificada | Alta (7.5) | 2.4% | — | Dcscripts DcforumDcscripts Dcforum 2000 | 2/7/2001 | 16/6/2026 | dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Allaire Forums | 12/3/2001 | 16/6/2026 | The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Extropia BBS Forum.cgi | 12/3/2001 | 16/6/2026 | Directory traversal vulnerability in eXtropia bbs_forum.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the file parameter. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Markus Triska Cgiforum | 9/1/2001 | 16/6/2026 | Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files via a .. (dot dot) attack in the "thesection" parameter. | |
| Modificada | Media (6.4) | 9.3% | 💥 Exploit | Dcscripts Dcforum | 9/1/2001 | 16/6/2026 | DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a malformed "forum" variable. | |
| Modificada | Media (6.4) | 2.5% | — | Allaire Forums | 3/4/2000 | 16/6/2026 | Allaire Forums 2.0.5 allows remote attackers to bypass access restrictions to secure conferences via the rightAccessAllForums or rightModerateAllForums variables. |