Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.82%—Xmbforum2 XMB19/4/202117/6/2026
XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.
ModificadaMedia (6.1)6.4%💥 ExploitFudforum19/3/202117/6/2026
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.
ModificadaMedia (6.1)7.6%💥 ExploitFudforum19/3/202117/6/2026
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.
ModificadaMedia (6.5)0.89%—Philips Coronary ToolsPhilips Dynamic Coronary RoadmapPhilips Interventional WorkspotPhilips Stentboost Live+126/1/202117/6/2026
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or…
ModificadaMedia (6.1)0.95%—Chronoengine Chronoforums16/11/202017/6/2026
Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.
ModificadaMedia (6.1)0.83%—Codoforum14/9/202017/6/2026
Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.'
ModificadaMedia (5.4)0.37%—MM Forum Project MM Forum7/7/202017/6/2026
The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF.
ModificadaMedia (5.3)0.85%—Mittwald Typo3 Forum7/7/202017/6/2026
The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control.
ModificadaCrítica (9.8)1.5%—Simplemachines Simple Machine Forum20/3/202017/6/2026
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
ModificadaMedia (5.4)0.53%—Codologic Codoforum16/2/202017/6/2026
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
ModificadaMedia (5.4)0.54%—Codologic Codoforum15/2/202017/6/2026
Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over…
ModificadaMedia (6.1)0.76%—Codologic Codoforum13/2/202017/6/2026
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.
ModificadaMedia (6.1)0.99%—Simplemachines Simple Machines Forum12/2/202016/6/2026
Simple Machines Forum (SMF) through 2.0.5 has XSS
ModificadaMedia (5.4)1.9%💥 ExploitVanillaforums Vanilla10/2/202017/6/2026
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
ModificadaMedia (4.9)3.8%💥 ExploitSimplemachines Simple Machines Forum7/2/202016/6/2026
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
ModificadaMedia (6.1)0.80%—Vanillaforums Vanilla5/2/202016/6/2026
Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter.
ModificadaAlta (7.2)8.8%💥 ExploitFudforum27/1/202016/6/2026
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
ModificadaCrítica (9.8)2.0%—Vanillaforums Vanilla22/1/202016/6/2026
An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.
ModificadaAlta (7.5)1.7%—Vanillaforums Vanilla22/1/202016/6/2026
An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.
ModificadaAlta (8.8)0.51%—Anelectron Advanced Electron Forums22/1/202016/6/2026
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
ModificadaMedia (6.5)1.3%—Simplemachines Simple Machines Forum22/1/202017/6/2026
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
ModificadaAlta (7.2)1.7%💥 ExploitSimplemachines Simple Machines Forum15/1/202016/6/2026
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain…
ModificadaAlta (7.5)1.8%—Pyforum Project Pyforum15/1/202016/6/2026
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
ModificadaCrítica (9.8)1.7%💥 ExploitSimplemachines Simple Machine Forum15/1/202016/6/2026
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
ModificadaMedia (6.1)1.8%💥 PoCCodologic Codoforum7/1/202017/6/2026
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.
Orbitaley — Vulnerabilidades