Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.75%—Emiloimagtolis Online Discussion Forum30/5/202417/6/2026
A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AnalizadaCrítica (9.8)0.47%—Gvectors Wpforo Forum17/5/202417/6/2026
Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.
AnalizadaMedia (6.9)0.83%—Razormist Online Discussion Forum Site16/5/202417/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaBaja (3.5)0.39%—Fudforum17/4/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.
AnalizadaMedia (6.1)0.37%—Fudforum17/4/202417/6/2026
FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php.
AnalizadaMedia (5.4)0.43%—Codologic Codoforum15/4/202417/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.
AnalizadaAlta (7.2)0.86%—Codologic Codoforum15/4/202417/6/2026
An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaAlta (8.8)0.24%—Asgaros Forum15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.8.0.
AnalizadaCrítica (9.8)1.0%—Razormist Online Discussion Forum Site20/3/202417/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file /uupdate.php. The manipulation of the argument ima leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaMedia (4.3)0.24%—Forumone Wp-cfm7/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1.7.8.
ModificadaCrítica (9.8)0.58%—Asgaros Forum24/1/202417/6/2026
Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.
ModificadaAlta (8.8)0.27%—Gvectors Wpforo Forum30/11/202317/6/2026
Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Accessing Functionality Not Properly Constrained by ACLs leading to forced all users log out.This issue affects wpForo Forum: from n/a through 2.2.6.
ModificadaMedia (5.4)0.38%—Gvectors Wpforo Forum30/11/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gVectors Team wpForo Forum allows Stored XSS.This issue affects wpForo Forum: from n/a through 2.2.3.
ModificadaCrítica (9.8)2.0%—Asgaros Forum27/11/202317/6/2026
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), potentially leading to remote code execution.
ModificadaMedia (6.1)1.1%💥 ExploitPhpjabbers PHP Forum Script30/8/202317/6/2026
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaMedia (6.1)0.84%💥 ExploitGvectors Wpforo Forum24/7/202317/6/2026
The wpForo Forum WordPress plugin before 2.1.9 does not escape some request parameters while in debug mode, leading to a Reflected Cross-Site Scripting vulnerability.
ModificadaMedia (6.1)0.48%—Gzscripts GZ Forum Script10/7/202317/6/2026
A vulnerability was found in GZ Scripts GZ Forum Script 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /preview.php. The manipulation of the argument catid/topicid/topic/topic_message/free_name leads to cross site scripting. The attack may be launched remotely. The…
ModificadaMedia (6.1)0.36%—Simplephpscripts Simple Forum PHP7/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The associated…
ModificadaAlta (8.8)61%—Gvectors Wpforo Forum9/6/202317/6/2026
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it…
AnalizadaAlta (8.8)0.84%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Discussion Forum Site 1.0. This affects an unknown part of the file admin\posts\view_post.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (8.8)0.78%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user\manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaAlta (8.8)0.75%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file posts\manage_post.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaAlta (8.8)0.84%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been classified as critical. Affected is an unknown function of the file admin\user\manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaAlta (8.8)0.78%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0 and classified as critical. This issue affects some unknown processing of the file admin\posts\manage_post.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed…
AnalizadaAlta (8.8)0.78%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability has been found in SourceCodester Online Discussion Forum Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin\categories\view_category.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been…
Orbitaley — Vulnerabilidades