Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Myupb Flat PHP Board | 17/12/2007 | 16/6/2026 | index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Flat PHP Board | 17/12/2007 | 16/6/2026 | Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials via a direct request for the username php file for any user account in users/. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Myupb Flat PHP Board | 17/12/2007 | 16/6/2026 | Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE:… | |
| Modificada | Media (6.8) | 2.3% | — | Picoflat CMS | 10/11/2007 | 16/6/2026 | index.php in Domenico Mancini PicoFlat CMS before 0.4.18 allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. NOTE: this can be leveraged to bypass authentication and upload files by including pico_insert.php or unspecified other administrative… | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Flatnuke3 | 1/11/2007 | 16/6/2026 | Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. | |
| Modificada | Media (6) | 3.8% | 💥 Exploit | Flatnuke3 | 1/11/2007 | 16/6/2026 | Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php file in a subdirectory of Download/ by saving a description and setting fneditmode to 1. NOTE: unauthenticated remote attackers can exploit… | |
| Modificada | Media (4.3) | 0.88% | 💥 Exploit | Flatnuke3 | 1/11/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via requests containing the pathname in the dir parameter and the filename in the ffile parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Flatnuke3 | 1/11/2007 | 16/6/2026 | index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | Picoflat CMS | 12/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pagina parameter. | |
| Modificada | Media (4.3) | 0.56% | — | Flatnuke | 26/9/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index.php in FlatNuke 2.6, and possibly 3, allows remote attackers to change the password and privilege level of arbitrary accounts via the user parameter and modified (1) regpass and (2) level parameters in a none_Login action, as demonstrated by using a Flash object… | |
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Mambo Flatmenu | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (10) | 4.4% | 💥 Exploit | Flat Chat | 10/3/2007 | 16/6/2026 | Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbitrary PHP code via the Chat Name field, which is inserted into online.txt and included by users.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.6) | 2.3% | 💥 Exploit | Flatnuke | 18/7/2006 | 16/6/2026 | The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file. | |
| Modificada | Alta (7.5) | 4.3% | — | PDF Tools AG PDF Form Filling AND Flattening Tool | 24/5/2006 | 16/6/2026 | Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names. | |
| Modificada | Alta (10) | 2.8% | — | Flatnuke | 21/12/2005 | 16/6/2026 | FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to gain privileges by obtaining the password hash (possibly via CVE-2005-2813), then calculating the credentials and including them in the… | |
| Modificada | Media (4) | 4.6% | 💥 Exploit | Flatnuke | 21/12/2005 | 16/6/2026 | verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into the body parameter. NOTE: if a FlatNuke administrator is normally assumed to be able to modify arbitrary content, then this issue does not… | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Flatnuke | 13/12/2005 | 16/6/2026 | Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Johannes F. Kuhlmann Flatfrag | 4/11/2005 | 16/6/2026 | Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1) version, (2) name, and (3) model fields. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Johannes F. Kuhlmann Flatfrag | 4/11/2005 | 16/6/2026 | FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference. | |
| Modificada | Media (4.3) | 1.2% | — | Flatnuke | 28/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of CVE-2005-3306. | |
| Modificada | Media (4.3) | 1.2% | — | Flatnuke | 26/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that this XSS is a resultant vulnerability of CVE-2005-3307. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | FlatnukeAI | 26/10/2005 | 16/6/2026 | Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation. | |
| Modificada | Media (6.4) | 1.8% | — | Flatnuke | 7/9/2005 | 16/6/2026 | print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) PRN, (4) COM1, or (5) LPT1. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Flatnuke | 7/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php. | |
| Modificada | Media (5) | 6.9% | 💥 Exploit | Flatnuke | 7/9/2005 | 16/6/2026 | Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php. |