Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.82% | — | Xmbforum2 XMB | 19/4/2021 | 17/6/2026 | XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16. | |
| Modificada | Media (6.1) | 6.4% | 💥 Exploit | Fudforum | 19/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | |
| Modificada | Media (6.1) | 7.6% | 💥 Exploit | Fudforum | 19/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | |
| Modificada | Media (6.5) | 0.89% | — | Philips Coronary ToolsPhilips Dynamic Coronary RoadmapPhilips Interventional WorkspotPhilips Stentboost Live+1 | 26/1/2021 | 17/6/2026 | Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or… | |
| Modificada | Media (6.1) | 0.95% | — | Chronoengine Chronoforums | 16/11/2020 | 17/6/2026 | Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed. | |
| Modificada | Media (6.1) | 0.83% | — | Codoforum | 14/9/2020 | 17/6/2026 | Codoforum 4.8.3 allows HTML Injection in the 'admin dashboard Manage users Section.' | |
| Modificada | Media (5.4) | 0.37% | — | MM Forum Project MM Forum | 7/7/2020 | 17/6/2026 | The mm_forum extension through 1.9.5 for TYPO3 allows XSS that can be exploited via CSRF. | |
| Modificada | Media (5.3) | 0.85% | — | Mittwald Typo3 Forum | 7/7/2020 | 17/6/2026 | The typo3_forum extension before 1.2.1 for TYPO3 has Incorrect Access Control. | |
| Modificada | Crítica (9.8) | 1.5% | — | Simplemachines Simple Machine Forum | 20/3/2020 | 17/6/2026 | An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls. | |
| Modificada | Media (5.4) | 0.53% | — | Codologic Codoforum | 16/2/2020 | 17/6/2026 | Codoforum 4.8.8 allows self-XSS via the title of a new topic. | |
| Modificada | Media (5.4) | 0.54% | — | Codologic Codoforum | 15/2/2020 | 17/6/2026 | Codologic Codoforum through 4.8.4 allows a DOM-based XSS. While creating a new topic as a normal user, it is possible to add a poll that is automatically loaded in the DOM once the thread/topic is opened. Because session cookies lack the HttpOnly flag, it is possible to steal authentication cookies and take over… | |
| Modificada | Media (6.1) | 0.76% | — | Codologic Codoforum | 13/2/2020 | 17/6/2026 | Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover. | |
| Modificada | Media (6.1) | 0.99% | — | Simplemachines Simple Machines Forum | 12/2/2020 | 16/6/2026 | Simple Machines Forum (SMF) through 2.0.5 has XSS | |
| Modificada | Media (5.4) | 1.9% | 💥 Exploit | Vanillaforums Vanilla | 10/2/2020 | 17/6/2026 | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. | |
| Modificada | Media (4.9) | 3.8% | 💥 Exploit | Simplemachines Simple Machines Forum | 7/2/2020 | 16/6/2026 | File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config. | |
| Modificada | Media (6.1) | 0.80% | — | Vanillaforums Vanilla | 5/2/2020 | 16/6/2026 | Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. | |
| Modificada | Alta (7.2) | 8.8% | 💥 Exploit | Fudforum | 27/1/2020 | 16/6/2026 | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | |
| Modificada | Crítica (9.8) | 2.0% | — | Vanillaforums Vanilla | 22/1/2020 | 16/6/2026 | An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. | |
| Modificada | Alta (7.5) | 1.7% | — | Vanillaforums Vanilla | 22/1/2020 | 16/6/2026 | An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. | |
| Modificada | Alta (8.8) | 0.51% | — | Anelectron Advanced Electron Forums | 22/1/2020 | 16/6/2026 | A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions. | |
| Modificada | Media (6.5) | 1.3% | — | Simplemachines Simple Machines Forum | 22/1/2020 | 17/6/2026 | An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links. | |
| Modificada | Alta (7.2) | 1.7% | 💥 Exploit | Simplemachines Simple Machines Forum | 15/1/2020 | 16/6/2026 | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain… | |
| Modificada | Alta (7.5) | 1.8% | — | Pyforum Project Pyforum | 15/1/2020 | 16/6/2026 | A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user. | |
| Modificada | Crítica (9.8) | 1.7% | 💥 Exploit | Simplemachines Simple Machine Forum | 15/1/2020 | 16/6/2026 | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | |
| Modificada | Media (6.1) | 1.8% | 💥 PoC | Codologic Codoforum | 7/1/2020 | 17/6/2026 | Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page. |