Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.85%—Kent-web WEB Forum24/10/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in KENT-WEB WEB FORUM before 5.1 allow remote attackers to inject arbitrary web script or HTML via (1) an e-mail address field or (2) a cookie, a related issue to CVE-2011-3383, CVE-2011-3983, and CVE-2011-3984.
ModificadaMedia (4.3)2.0%—Kent-web WEB Forum24/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "web form entries."
ModificadaMedia (4.3)1.7%—Kent-web WEB Forum24/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to cookies.
ModificadaMedia (4.3)1.0%—Kent-web WEB Forum24/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB FORUM 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to "the web page to be output."
ModificadaAlta (7.5)2.6%—Minihttp WEB Forum File Sharing Sever Powerpack28/10/200616/6/2026
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.
ModificadaAlta (7.5)1.4%—Vego WEB Forum3/1/200616/6/2026
SQL injection vulnerability in (1) functions.php, (2) functions_update.php, and (3) functions_display.php in VEGO Web Forum 1.26 and earlier allows remote attackers to execute arbitrary SQL commands via the theme_id parameter in index.php.
ModificadaAlta (7.5)1.3%—Wowbb WEB Forum14/5/200516/6/2026
SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.
ModificadaMedia (5)1.1%—Php-post WEB Forum2/5/200516/6/2026
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
ModificadaMedia (4.3)0.94%—Php-post WEB Forum2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI31/12/200416/6/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModificadaAlta (7.5)1.1%—Wowbb WEB Forum31/12/200416/6/2026
Multiple SQL injection vulnerabilities in WowBB Forum 1.61 allow remote attackers to execute arbitrary SQL commands via the (1) sort_by or (2) page parameters to view_user.php, or the (3) forum_id parameter to view_topic.php. NOTE: the sort_by vector was later reported to be present in WowBB 1.65.
ModificadaMedia (4.3)0.99%—Wowbb WEB Forum31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WowBB Forum 1.61 allow remote attackers to inject arbitrary web script or HTML via the (1) country parameter to view_user.php, (2) show parameter to view_forum.php, (3) letter parameter to view_user.php, (4) highlight parameter to view_topic.php, (5) show…
ModificadaMedia (5)1.5%—Minihttpserver.net WEB Forums Server31/12/200416/6/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModificadaAlta (7.5)1.2%—Devoybb WEB Forum31/12/200416/6/2026
SQL injection vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaAlta (7.5)9.3%—Aborior Encore WEB Forum31/12/200416/6/2026
display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.
ModificadaMedia (4.3)1.2%—Devoybb WEB Forum31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in DevoyBB Web Forum 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.