Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.75% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Discussion Forum Site 1.0. This affects an unknown part of the file admin\categories\manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Alta (8.8) | 0.78% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Discussion Forum Site 1.0. Affected by this issue is some unknown functionality of the file classes\Users.php?f=registration. The manipulation of the argument username leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.4) | 0.64% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (5.4) | 0.61% | — | Razormist Online Discussion Forum Site | 7/6/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.26% | — | Asgaros Forum | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Qbian61 Forum-java Project Qbian61 Forum-java | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML via editing the article content in the "article editor" page. | |
| Modificada | Alta (8.8) | 0.88% | — | Prestashop XEN Forum | 6/3/2023 | 17/6/2026 | In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0. | |
| Modificada | Alta (8.8) | 0.73% | — | Niterforum | 15/2/2023 | 17/6/2026 | An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges. | |
| Modificada | Media (5.4) | 0.67% | — | Yetanotherforum Yaf.net | 2/2/2023 | 17/6/2026 | A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Media (5.4) | 0.69% | — | Yetanotherforum Yaf.net | 27/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross site scripting. The attack may be… | |
| Modificada | Media (6.1) | 0.54% | — | Nim-lang NIMNim-lang Nimforum | 13/1/2023 | 17/6/2026 | An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum… | |
| Modificada | Crítica (9.8) | 0.70% | — | Forumhulp Search Results | 7/1/2023 | 17/6/2026 | A vulnerability was found in ForumHulp searchresults. It has been rated as critical. Affected by this issue is the function list_keywords of the file event/listener.php. The manipulation of the argument word leads to sql injection. The name of the patch is dd8a312bb285ad9735a8e1da58e9e955837b7322. It is recommended to… | |
| Modificada | Alta (8.8) | 0.96% | — | Gvectors Wpforo Forum | 17/11/2022 | 17/6/2026 | Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. | |
| Modificada | Alta (8.8) | 0.47% | — | Gvectors Wpforo Forum | 17/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress. | |
| Modificada | Media (5.4) | 0.28% | — | Gvectors Wpforo Forum | 8/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion. | |
| Modificada | Media (4.3) | 0.50% | — | Gvectors Wpforo Forum | 8/11/2022 | 17/6/2026 | Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public. | |
| Modificada | Media (4.3) | 0.53% | — | Gvectors Wpforo Forum | 8/11/2022 | 17/6/2026 | Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved. | |
| Modificada | Alta (8.8) | 0.51% | — | Gvectors Wpforo Forum | 9/9/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. | |
| Modificada | Crítica (9.3) | 1.5% | — | Onyxforum Project Onyxforum | 11/7/2022 | 17/6/2026 | The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.2) | 32% | 💥 Exploit | Codologic Codoforum | 7/7/2022 | 17/6/2026 | Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel. | |
| Modificada | Media (4.4) | 0.33% | — | Khoros Lithium Forum | 28/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has… | |
| Modificada | Crítica (9.8) | 2.4% | 💥 PoC | Online Discussion Forum Project Online Discussion Forum | 17/6/2022 | 17/6/2026 | Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php. | |
| Modificada | Alta (8.8) | 0.71% | — | Jforum | 16/6/2022 | 9/7/2026 | JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts. | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts. | |
| Modificada | Media (6.5) | 0.85% | 💥 PoC | Razormist Online Discussion Forum Site | 16/6/2022 | 17/6/2026 | An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts. |