Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | — | Powie Pforum | 30/9/2008 | 16/6/2026 | SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Tinyphpforum | 24/2/2007 | 16/6/2026 | Directory traversal vulnerability in profile.php in TinyPHPforum 3.6 and earlier allows remote attackers to include and execute arbitrary files via ".." sequences in the uname parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Powie Pforum | 22/11/2006 | 16/6/2026 | SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | Ralph Capper Tinyphpforum | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ralph Capper Tiny PHP Forum (TPF) 3.6 allow remote attackers to inject arbitrary web script or HTML via (1) the uname parameter in a view action in profile.php and (2) a login name. NOTE: the "Access to hash password" issue is already covered by CVE-2006-0103. | |
| Modificada | Media (4.3) | 1.4% | — | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TinyPHPForum (TPF) 3.6 and earlier allows remote attackers to inject arbitrary web script via a javascript: scheme in an "[a]" bbcode tag, possibly the txt parameter to action.php. | |
| Modificada | Media (5) | 2.6% | — | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | Directory traversal vulnerability in TinyPHPForum 3.6 and earlier allows remote attackers to create a new user account, create a new topic, or view the profile of a user account, as demonstrated via a .. (dot dot) in the uname parameter to profile.php. | |
| Modificada | Media (5) | 4.1% | — | Ralph Capper Tinyphpforum | 6/1/2006 | 16/6/2026 | TinyPHPForum 3.6 and earlier stores the (1) users/[USERNAME].hash and (2) users/[USERNAME].email files under the web root with insufficient access control, which allows remote attackers to list all registered users and possibly obtain other sensitive information. | |
| Modificada | Alta (7.5) | 1.2% | — | W2B Phpforumpro | 8/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in phpForumPro 2.2 allows remote attackers to execute arbitrary SQL commands via the (1) parent and (2) day parameters. | |
| Modificada | Media (6.8) | 2.4% | — | Powie Pforum | 16/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PForum before 1.26 allows remote attackers to inject arbitrary web script or HTML via the (1) IRC Server or (2) AIM ID fields in the user profile. | |
| Modificada | Alta (7.5) | 1.4% | — | Phpforum | 18/8/2003 | 16/6/2026 | mainfile.php in phpforum 2 RC-1, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by modifying the MAIN_PATH parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 7.2% | — | Powie Pforum | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username. | |
| Modificada | Alta (10) | 2.4% | — | Powie Pforum | 31/5/2002 | 16/6/2026 | pforum 1.14 and earlier does not explicitly enable PHP magic quotes, which allows remote attackers to bypass authentication and gain administrator privileges via an SQL injection attack when the PHP server is not configured to use magic quotes by default. |