Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.5) | 0.39% | — | Fudforum | 17/4/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SQL statements field under /adm/admsql.php. | |
| Analizada | Media (6.1) | 0.37% | — | Fudforum | 17/4/2024 | 17/6/2026 | FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php. | |
| Modificada | Media (4.8) | 0.56% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Panel. | |
| Modificada | Media (4.8) | 0.56% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. | |
| Modificada | Alta (7.2) | 25% | — | Fudforum | 6/6/2022 | 17/6/2026 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel. | |
| Modificada | Media (5.4) | 0.47% | — | Fudforum | 6/5/2022 | 17/6/2026 | FUDforum 3.1.1 is vulnerable to Stored XSS. | |
| Modificada | Media (6.1) | 6.4% | — | Fudforum | 19/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "author" parameter. | |
| Modificada | Media (6.1) | 7.6% | — | Fudforum | 19/3/2021 | 17/6/2026 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "srch" parameter. | |
| Modificada | Alta (7.2) | 8.8% | — | Fudforum | 27/1/2020 | 16/6/2026 | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | |
| Modificada | Crítica (9) | 5.4% | — | Fudforum | 13/11/2019 | 17/6/2026 | FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the… | |
| Modificada | Crítica (9) | 8.2% | — | Fudforum | 12/11/2019 | 17/6/2026 | FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin visits user information under "User Manager" in the control panel, the payload will execute. This will… | |
| Modificada | Baja (2.6) | 1.2% | — | FudforumIlia Alshanetsky Fudforum | 16/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 1.9% | — | Ilia Alshanetsky Fudforum | 2/9/2005 | 16/6/2026 | The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code. | |
| Modificada | Media (5) | 1.6% | — | Ilia Alshanetsky Fudforum | 17/8/2005 | 16/6/2026 | FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter. | |
| Modificada | Media (5) | 6.6% | — | Ilia Alshanetsky Fudforum | 11/4/2003 | 16/6/2026 | admbrowse.php in FUDforum before 2.2.0 allows remote attackers to create or delete files via URL-encoded pathnames in the cur and dest parameters. | |
| Modificada | Media (5) | 3.5% | — | Ilia Alshanetsky Fudforum | 11/4/2003 | 16/6/2026 | tmp_view.php in FUDforum before 2.2.0 allows remote attackers to read arbitrary files via an absolute pathname in the file parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Ilia Alshanetsky Fudforum | 11/4/2003 | 16/6/2026 | SQL injection vulnerabilities in FUDforum before 2.2.0 allow remote attackers to perform unauthorized database operations via (1) report.php, (2) selmsg.php, and (3) showposts.php. |