Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.5)0.39%—Fudforum17/4/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php.
AnalizadaMedia (6.1)0.37%—Fudforum17/4/202417/6/2026
FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php.
ModificadaMedia (4.8)0.56%—Fudforum6/6/202217/6/2026
FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel.
ModificadaMedia (4.8)0.56%—Fudforum6/6/202217/6/2026
FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
ModificadaAlta (7.2)25%—Fudforum6/6/202217/6/2026
FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.
ModificadaMedia (5.4)0.47%—Fudforum6/5/202217/6/2026
FUDforum 3.1.1 is vulnerable to Stored XSS.
ModificadaMedia (6.1)6.4%—Fudforum19/3/202117/6/2026
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter.
ModificadaMedia (6.1)7.6%—Fudforum19/3/202117/6/2026
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter.
ModificadaAlta (7.2)8.8%—Fudforum27/1/202016/6/2026
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
ModificadaCrítica (9)5.4%—Fudforum13/11/201917/6/2026
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the…
ModificadaCrítica (9)8.2%—Fudforum12/11/201917/6/2026
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will…
ModificadaBaja (2.6)1.2%—FudforumIlia Alshanetsky Fudforum16/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)1.9%—Ilia Alshanetsky Fudforum2/9/200516/6/2026
The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.
ModificadaMedia (5)1.6%—Ilia Alshanetsky Fudforum17/8/200516/6/2026
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
ModificadaMedia (5)6.6%—Ilia Alshanetsky Fudforum11/4/200316/6/2026
admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters.
ModificadaMedia (5)3.5%—Ilia Alshanetsky Fudforum11/4/200316/6/2026
tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter.
ModificadaAlta (7.5)2.1%—Ilia Alshanetsky Fudforum11/4/200316/6/2026
SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php.