Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.8%💥 ExploitEduforge Emergecolab28/1/200916/6/2026
Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php.
ModificadaAlta (7.5)1.6%—Gforge2/1/200916/6/2026
SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.
ModificadaAlta (9.3)1.4%—Sourceforge Emule X-ray29/5/200816/6/2026
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.
ModificadaMedia (4.6)0.73%💥 ExploitGforge18/5/200816/6/2026
The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.
ModificadaAlta (7.5)2.8%💥 ExploitSourceforge WEB Slider18/5/200816/6/2026
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
ModificadaAlta (7.5)2.3%—IBM Rational Build Forge9/5/200816/6/2026
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.
ModificadaAlta (7.5)0.97%💥 ExploitPhpforge PHP Forge6/5/200816/6/2026
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.
ModificadaMedia (4.3)1.5%💥 ExploitSilver-forge Neptune WEB Server11/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.
ModificadaMedia (5.8)1.8%💥 ExploitSourceforge Phpmyclub30/1/200816/6/2026
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the top-level URI.
ModificadaAlta (7.5)2.1%—Gforge15/1/200816/6/2026
SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.
ModificadaMedia (6.4)1.2%—Sourceforge CreammonkeySourceforge Greasekit4/1/200816/6/2026
Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to read the configuration, modify the configuration, or send an HTTP request via the (1) GM_addStyle, (2) GM_log, (3) GM_openInTab, (4) GM_setValue, (5) GM_getValue, or (6)…
ModificadaBaja (3.3)0.30%—Gforge8/11/200716/6/2026
gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.
ModificadaMedia (4.3)1.3%—Gforge5/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.
ModificadaMedia (6.8)1.5%💥 ExploitGforge18/9/200716/6/2026
SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.
ModificadaAlta (7.5)2.0%💥 ExploitGforge6/9/200716/6/2026
SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)1.8%—Gforge29/5/200716/6/2026
plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.
ModificadaAlta (7.5)2.4%💥 ExploitGforge Garennes26/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter to index.php in (1) cpe/, (2) direction/, or (3) professeurs/.
ModificadaMedia (6.8)0.84%💥 ExploitSourceforge Jgbbs21/3/200716/6/2026
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than CVE-2007-1440. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)3.4%—Sourceforge Wordperfect Document Importer-exporter16/3/200716/6/2026
Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted WordPerfect file, a different vulnerability than…
ModificadaMedia (6.8)1.1%—Sourceforge Webmplayer2/3/200716/6/2026
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.
ModificadaMedia (5)0.92%—Sourceforge Putmail2/3/200716/6/2026
putmail.py in Putmail before 1.4 does not detect when a user attempts to use TLS with a server that does not support it, which causes putmail.py to send the username and password in plaintext while the user believes encryption is in use, and allows remote attackers to obtain sensitive information.
ModificadaMedia (4.3)0.89%—THE WAR Forge Warforge.news12/2/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML and web script via the (1) title and (2) newspost parameters to (a) newsadd.php, and the (3) name, title, and (4) comment parameters to (b) news.php, a different set of vectors than CVE-2006-1818.…
ModificadaAlta (9.3)4.8%—Rubyforge Rubygems24/1/200716/6/2026
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
ModificadaMedia (6.8)2.0%—Gforge11/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in search/advanced_search.php in GForge 4.5.11 allows remote attackers to inject arbitrary web script or HTML via the words parameter.
ModificadaAlta (7.5)3.2%💥 ExploitOpen Source Technology Group Sourceforge27/10/200616/6/2026
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.
Orbitaley — Vulnerabilidades