Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.49% | — | Galaxy Software Services Corporation Vitals ESP Forum ModuleAI | 20/10/2025 | 30/9/2026 | An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services Corporation Vitals ESP Forum Module through 1.3 version allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Alta (7.6) | 0.32% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.1) | 0.12% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Modificada | Media (6.1) | 1.1% | — | Phpjabbers PHP Forum Script | 30/8/2023 | 17/6/2026 | phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Pyforum Project Pyforum | 15/1/2020 | 16/6/2026 | A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user. | |
| Modificada | Media (4.3) | 1.5% | — | Rocomotion P BoardRocomotion P Diary RRocomotion P ForumRocomotion P Link+6 | 20/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM… | |
| Modificada | Media (4.3) | 1.0% | — | Frank-karau Phpfk PHP Forum | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.4% | — | Fipsasp Fipsforum | 2/3/2010 | 16/6/2026 | fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _database/forumFips.mdb. | |
| Modificada | Media (4.3) | 1.0% | — | Pyforum | 23/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to inject arbitrary web script or HTML via crafted BBcode (1) img or (2) url tags, which are not properly handled when a post is viewed. | |
| Modificada | Media (6.8) | 0.58% | — | Pyforum | 23/12/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attackers to hijack the authentication of victims for requests that change passwords, and other unspecified requests, via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | Rocomotion P Forum | 22/12/2009 | 16/6/2026 | Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Fahlstad Wp-forum | 18/12/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the search_max parameter in a search action to the default URI, related to wpf.class.php; (2) the forum parameter to an unspecified component, related to… | |
| Modificada | Media (4.3) | 1.5% | — | Uloki PHP Forum | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Codetoad ASP Forum Script | 3/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ASP Forum Script allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id parameter to (a) new_message.asp and (b) messages.asp, and the (2) query string to default.asp. | |
| Modificada | Alta (7.5) | 0.97% | — | Codetoad ASP Forum Script | 3/8/2009 | 16/6/2026 | SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL commands via the message_id parameter. | |
| Modificada | Media (5.1) | 0.88% | — | Myphp Forum | 1/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a confirm action, the (2) user parameter in a newconfirm action, and (3) reqpwd action to member.php; and the (4) quote parameter in a post action and (5) pid… | |
| Modificada | Alta (7.5) | 1.1% | — | Go4i Go41.net ASP Forum | 25/3/2009 | 16/6/2026 | SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter. | |
| Modificada | Media (6.8) | 3.5% | — | Wordpress WP Forum | 23/1/2008 | 16/6/2026 | SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI. | |
| Modificada | Media (6.8) | 0.85% | — | Myphp Forum | 8/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors. | |
| Modificada | Media (6.8) | 0.96% | — | Myphp Forum | 4/1/2008 | 16/6/2026 | SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the member.php vector is already covered by CVE-2005-0413. | |
| Modificada | Baja (2.6) | 1.0% | — | Simple PHP Forum | 18/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile. | |
| Modificada | Media (6.8) | 4.4% | — | Maran PHP Forum | 24/4/2007 | 16/6/2026 | Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execute arbitrary PHP files via a trailing %00 in a filename in the page parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Simple PHP Forum | 2/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple PHP Forum before 0.4 allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) logon_user.php and (2) update_profile.php. | |
| Modificada | Alta (10) | 1.8% | — | Kervancilar Aspmforum | 4/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASPMForum allow remote attackers to execute arbitrary SQL commands via (1) the soruid parameter in forum2.asp, (2) the ak parameter in kullanicilistesi.asp, (3) the kelimeler parameter in aramayap.asp, and (4) the kullaniciadi parameter in giris.asp; and allow remote… | |
| Modificada | Alta (7.5) | 1.2% | — | Fipsasp Fipsforum | 26/11/2006 | 16/6/2026 | SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the kat parameter. |