Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.75%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Discussion Forum Site 1.0. This affects an unknown part of the file admin\categories\manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has…
AnalizadaAlta (8.8)0.78%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Online Discussion Forum Site 1.0. Affected by this issue is some unknown functionality of the file classes\Users.php?f=registration. The manipulation of the argument username leads to sql injection. The attack may be launched remotely.…
AnalizadaMedia (5.4)0.64%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Discussion Forum Site 1.0. Affected by this vulnerability is an unknown functionality of the file admin\posts\manage_post.php. The manipulation of the argument title leads to cross site scripting. The attack can be launched remotely. The…
AnalizadaMedia (5.4)0.61%—Razormist Online Discussion Forum Site7/6/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Online Discussion Forum Site 1.0. Affected is an unknown function of the file admin\posts\manage_post.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaAlta (8.8)0.26%—Asgaros Forum22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Thomas Belser Asgaros Forum plugin <= 2.2.0 versions.
ModificadaMedia (6.1)0.36%—Qbian61 Forum-java Project Qbian61 Forum-java1/5/202317/6/2026
Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML via editing the article content in the "article editor" page.
ModificadaAlta (8.8)0.88%—Prestashop XEN Forum6/3/202317/6/2026
In the module "Xen Forum" (xenforum) for PrestaShop, an authenticated user can perform SQL injection in versions up to 2.13.0.
ModificadaAlta (8.8)0.73%—Niterforum15/2/202317/6/2026
An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/java/cn/niter/forum/controller/AdminController.java, allows attackers to gain escalated privileges.
ModificadaMedia (5.4)0.67%—Yetanotherforum Yaf.net2/2/202317/6/2026
A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaMedia (5.4)0.69%—Yetanotherforum Yaf.net27/1/202317/6/2026
A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross site scripting. The attack may be…
ModificadaMedia (6.1)0.54%—Nim-lang NIMNim-lang Nimforum13/1/202317/6/2026
An issue was discovered in Nim before 1.6.2. The RST module of the Nim language stdlib, as used in NimForum and other products, permits the javascript: URI scheme and thus can lead to XSS in some applications. (Nim versions 1.6.2 and later are fixed; there may be backports of the fix to some earlier versions. NimForum…
ModificadaCrítica (9.8)0.70%—Forumhulp Search Results7/1/202317/6/2026
A vulnerability was found in ForumHulp searchresults. It has been rated as critical. Affected by this issue is the function list_keywords of the file event/listener.php. The manipulation of the argument word leads to sql injection. The name of the patch is dd8a312bb285ad9735a8e1da58e9e955837b7322. It is recommended to…
ModificadaAlta (8.8)0.96%—Gvectors Wpforo Forum17/11/202217/6/2026
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
ModificadaAlta (8.8)0.47%—Gvectors Wpforo Forum17/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
ModificadaMedia (5.4)0.28%—Gvectors Wpforo Forum8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
ModificadaMedia (4.3)0.50%—Gvectors Wpforo Forum8/11/202217/6/2026
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
ModificadaMedia (4.3)0.53%—Gvectors Wpforo Forum8/11/202217/6/2026
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
ModificadaAlta (8.8)0.51%—Gvectors Wpforo Forum9/9/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
ModificadaCrítica (9.3)1.5%—Onyxforum Project Onyxforum11/7/202217/6/2026
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.2)32%💥 ExploitCodologic Codoforum7/7/202217/6/2026
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin panel.
ModificadaMedia (4.4)0.33%—Khoros Lithium Forum28/6/202217/6/2026
A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has…
ModificadaCrítica (9.8)2.4%💥 PoCOnline Discussion Forum Project Online Discussion Forum17/6/202217/6/2026
Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.
ModificadaAlta (8.8)0.71%—Jforum16/6/20229/7/2026
JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.
ModificadaAlta (7.5)1.4%💥 PoCRazormist Online Discussion Forum Site16/6/202217/6/2026
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.
ModificadaMedia (6.5)0.85%💥 PoCRazormist Online Discussion Forum Site16/6/202217/6/2026
An issue in the save_users() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily create or update user accounts.
Orbitaley — Vulnerabilidades