Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.8% | — | Instantasp Instantforum | 19/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in InstantASP InstantForum.NET 4.1.3, 4.1.2, 4.1.1, 4.0.0, 4.1.0, and 3.4.0 allow remote attackers to inject arbitrary web script or HTML via the SessionID parameter to (1) Join.aspx or (2) Logon.aspx. | |
| Modificada | Media (5.4) | 0.30% | — | Fiatforum Fiat Forum | 22/9/2014 | 17/6/2026 | The FIAT Forum (aka com.tapatalk.fiatforumcom) application 3.8.41 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 0.96% | — | Tforum | 31/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in tForum b0.915 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a viewprofile action. | |
| Modificada | Alta (7.5) | 1.2% | — | Tforum | 31/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in tForum b0.915 allow remote attackers to execute arbitrary SQL commands via the (1) TopicID parameter to viewtopic.php, the (2) BoardID parameter to viewboard.php, or (3) CatID parameter to viewcat.php. | |
| Modificada | Media (4.3) | 0.92% | — | Courseforum Projectforum | 3/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CourseForum ProjectForum 7.0.1.3038 allows remote attackers to inject arbitrary web script or HTML via a crafted name of an object within a more object on a wiki page. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Tntforum TNT Forum | 28/11/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ttcms Ttforum | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | RBL Tforum | 31/1/2007 | 16/6/2026 | SQL injection vulnerability in tForum 2.00 in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) pass to user_confirm.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Axentforum | 19/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewposts.cfm in aXentForum II and earlier allows remote attackers to inject arbitrary web script or HTML via the startrow parameter. | |
| Modificada | Media (4.3) | 2.6% | — | Txtforum | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in txtForum 1.0.4-dev and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prev, (2) next, and (3) rand5 parameters in (a) index.php; the (4) r_username and (5) r_loc parameters in (b) new_topic.php; the (6) r_num, (7) r_family_name,… | |
| Modificada | Alta (7.5) | 1.5% | — | Txtforum | 14/3/2006 | 16/6/2026 | PHP remote file include vulnerability in common.php in txtForum 1.0.4-dev and earlier allows remote attackers to include and execute arbitrary PHP code via a URL in the skin parameter to login.php, and possibly other parameters to other PHP scripts, related to include statements in common.php. | |
| Modificada | Media (4.3) | 1.3% | — | Courseforum Projectforum | 17/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProjectForum 4.7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) fwd parameter in admin/adminsignin.html and (2) originalpageid parameter in admin/newpage.html associated with a group. | |
| Modificada | Alta (7.8) | 1.8% | — | Courseforum Projectforum | 17/12/2005 | 16/6/2026 | ProjectForum 4.7.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted pageid parameter to admin/versions.html. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Atlantpro.com Atlantforum | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in atl.cgi in AtlantForum 4.02 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) sch_allsubct, (2) before, and (3) ct parameters. | |
| Modificada | Media (5) | 1.1% | — | Petitforum | 31/12/2003 | 16/6/2026 | Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | |
| Modificada | Media (6.8) | 1.1% | — | Petitforum | 31/12/2003 | 16/6/2026 | message.php in Petitforum does not properly authenticate users, which allows remote attackers to impersonate forum users via a modified connect cookie. | |
| Modificada | Alta (7.5) | 1.1% | — | TtcmsTtcms Ttforum | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in Profile.php in ttCMS 2.2 and ttForum allows remote attackers to execute arbitrary SQL commands via the member name. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | TtcmsTtcms Ttforum | 31/12/2003 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ttCMS 2.2 and ttForum allow remote attackers to execute arbitrary PHP code via the (1) template parameter in News.php or (2) installdir parameter in install.php. | |
| Modificada | Alta (10) | 1.9% | — | Ttcms Ttforum | 9/6/2003 | 16/6/2026 | SQL injection vulnerability in ttForum allows remote attackers to execute arbitrary SQL and gain ttForum Administrator privileges via the Ignorelist-Textfield argument in the Preferences page. |