Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Eduforge Emergecolab | 28/1/2009 | 16/6/2026 | Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php. | |
| Modificada | Alta (7.5) | 1.6% | — | Gforge | 2/1/2009 | 16/6/2026 | SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable. | |
| Modificada | Alta (9.3) | 1.4% | — | Sourceforge Emule X-ray | 29/5/2008 | 16/6/2026 | Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.6) | 0.73% | 💥 Exploit | Gforge | 18/5/2008 | 16/6/2026 | The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Sourceforge WEB Slider | 18/5/2008 | 16/6/2026 | Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. | |
| Modificada | Alta (7.5) | 2.3% | — | IBM Rational Build Forge | 9/5/2008 | 16/6/2026 | IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phpforge PHP Forge | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Silver-forge Neptune WEB Server | 11/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Sourceforge Phpmyclub | 30/1/2008 | 16/6/2026 | Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI. | |
| Modificada | Alta (7.5) | 2.1% | — | Gforge | 15/1/2008 | 16/6/2026 | SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports. | |
| Modificada | Media (6.4) | 1.2% | — | Sourceforge CreammonkeySourceforge Greasekit | 4/1/2008 | 16/6/2026 | Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GM_addStyle, (2) GM_log, (3) GM_openInTab, (4) GM_setValue, (5) GM_getValue, or (6)… | |
| Modificada | Baja (3.3) | 0.30% | — | Gforge | 8/11/2007 | 16/6/2026 | gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (4.3) | 1.3% | — | Gforge | 5/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter. | |
| Modificada | Media (6.8) | 1.5% | 💥 Exploit | Gforge | 18/9/2007 | 16/6/2026 | SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Gforge | 6/9/2007 | 16/6/2026 | SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.8% | — | Gforge | 29/5/2007 | 16/6/2026 | plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Gforge Garennes | 26/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/. | |
| Modificada | Media (6.8) | 0.84% | 💥 Exploit | Sourceforge Jgbbs | 21/3/2007 | 16/6/2026 | SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 3.4% | — | Sourceforge Wordperfect Document Importer-exporter | 16/3/2007 | 16/6/2026 | Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than… | |
| Modificada | Media (6.8) | 1.1% | — | Sourceforge Webmplayer | 2/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php. | |
| Modificada | Media (5) | 0.92% | — | Sourceforge Putmail | 2/3/2007 | 16/6/2026 | putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 0.89% | — | THE WAR Forge Warforge.news | 12/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML and web script via the (1) title and (2) newspost parameters to (a) newsadd.php, and the (3) name, title, and (4) comment parameters to (b) news.php, a different set of vectors than CVE-2006-1818.… | |
| Modificada | Alta (9.3) | 4.8% | — | Rubyforge Rubygems | 24/1/2007 | 16/6/2026 | The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages. | |
| Modificada | Media (6.8) | 2.0% | — | Gforge | 11/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Open Source Technology Group Sourceforge | 27/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter. |