Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.85% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB FORUM before 5.1 allow remote attackers to inject arbitrary web script or HTML via (1) an e-mail address field or (2) a cookie, a related issue to CVE-2011-3383, CVE-2011-3983, and CVE-2011-3984. | |
| Modificada | Media (4.3) | 2.0% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries." | |
| Modificada | Media (4.3) | 1.7% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies. | |
| Modificada | Media (4.3) | 1.0% | — | Kent-web WEB Forum | 24/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "the web page to be output." | |
| Modificada | Alta (7.5) | 2.6% | — | Minihttp WEB Forum File Sharing Sever Powerpack | 28/10/2006 | 16/6/2026 | join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters. | |
| Modificada | Alta (7.5) | 1.4% | — | Vego WEB Forum | 3/1/2006 | 16/6/2026 | SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Wowbb WEB Forum | 14/5/2005 | 16/6/2026 | SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter. | |
| Modificada | Media (5) | 1.1% | — | Php-post WEB Forum | 2/5/2005 | 16/6/2026 | PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters. | |
| Modificada | Media (4.3) | 0.94% | — | Php-post WEB Forum | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.6) | 0.31% | — | Minihttpserver.net WEB Forums ServerAI | 31/12/2004 | 16/6/2026 | Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 1.1% | — | Wowbb WEB Forum | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65. | |
| Modificada | Media (4.3) | 0.99% | — | Wowbb WEB Forum | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show… | |
| Modificada | Media (5) | 1.5% | — | Minihttpserver.net WEB Forums Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash). | |
| Modificada | Alta (7.5) | 1.2% | — | Devoybb WEB Forum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 9.3% | — | Aborior Encore WEB Forum | 31/12/2004 | 16/6/2026 | display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable. | |
| Modificada | Media (4.3) | 1.2% | — | Devoybb WEB Forum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |