Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.30% | — | Fabricators Vanilla OS Core Image | 13/1/2026 | 5/7/2026 | fabricators Ltd Vanilla OS 2 Core image v1.1.0 was discovered to contain static keys for the SSH service, allowing attackers to possibly execute a man-in-the-middle attack during connections with other hosts. | |
| Modificada | Media (6.1) | 0.58% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher. | |
| Modificada | Media (6.1) | 0.66% | — | Vanillaforums Vanilla Forums | 22/6/2021 | 16/6/2026 | It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side. | |
| Modificada | Media (5.4) | 1.9% | — | Vanillaforums Vanilla | 10/2/2020 | 17/6/2026 | index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. | |
| Modificada | Media (6.1) | 0.80% | — | Vanillaforums Vanilla | 5/2/2020 | 16/6/2026 | Vanilla Forums 2.0.17.1 through 2.0.17.5 has XSS in /vanilla/index.php via the p parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Vanillaforums Vanilla | 22/1/2020 | 16/6/2026 | An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9. | |
| Modificada | Alta (7.5) | 1.7% | — | Vanillaforums Vanilla | 22/1/2020 | 16/6/2026 | An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled. | |
| Modificada | Baja (2.7) | 2.4% | — | Vanillaforums Vanilla | 21/3/2019 | 17/6/2026 | In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code under the context of the web server. | |
| Modificada | Media (5.4) | 0.81% | — | Vanillaforums Vanilla Forums | 2/3/2019 | 17/6/2026 | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any message on forum. | |
| Modificada | Alta (7.2) | 2.0% | — | Vanillaforums Vanilla | 23/11/2018 | 17/6/2026 | Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class. | |
| Modificada | Crítica (9.8) | 5.2% | — | Vanillaforums Vanilla | 3/11/2018 | 17/6/2026 | Vanilla 2.6.x before 2.6.4 allows remote code execution. | |
| Modificada | Media (6.1) | 0.68% | — | Vanillaforums Vanilla | 28/9/2018 | 17/6/2026 | Vanilla before 2.6.1 allows XSS via the email field of a profile. | |
| Modificada | Media (6.5) | 0.94% | — | Vanillaforums Vanilla | 3/9/2018 | 17/6/2026 | Vanilla before 2.6.1 allows SQL injection via an invitationID array to /profile/deleteInvitation, related to applications/dashboard/models/class.invitationmodel.php and applications/dashboard/controllers/class.profilecontroller.php. | |
| Modificada | Media (4.3) | 0.88% | — | Vanillaforums Vanilla Forums | 26/8/2018 | 17/6/2026 | In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items). | |
| Modificada | Alta (8) | 1.6% | — | Vanillaforums Vanilla Forums | 2/1/2018 | 17/6/2026 | Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access | |
| Modificada | Alta (7.5) | 84% | — | Vanillaforums Vanilla | 23/5/2017 | 17/6/2026 | The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request. | |
| Modificada | Media (4.3) | 1.8% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 25/2/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vanilla Forums before 2.0.18.13 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.1% | — | Vanillaforums Latestcomment | 23/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title. | |
| Modificada | Alta (7.5) | 5.7% | — | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection." | |
| Modificada | Alta (7.5) | 3.5% | — | Vanillaforums Vanilla | 10/5/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vanilla Forums before 2.0.18.8 allow remote attackers to execute arbitrary SQL commands via the parameter name in the Form/Email array to (1) entry/signin or (2) entry/passwordrequest. | |
| Modificada | Baja (3.5) | 1.1% | — | Vanillaforums VanillaVanillaforums Vanilla Forums | 15/11/2012 | 16/6/2026 | The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue. | |
| Modificada | Media (5) | 1.2% | — | Vanillaforums Vanilla | 24/9/2011 | 16/6/2026 | Vanilla 2.0.16 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Minify/min/utils.php and certain other files. | |
| Modificada | Media (6.4) | 1.0% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks. | |
| Modificada | Media (4.3) | 0.85% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to inject arbitrary web script or HTML via the p parameter to an unspecified component, a different vulnerability than CVE-2011-0526. | |
| Modificada | Media (5.8) | 0.96% | — | Vanillaforums Vanilla | 8/2/2011 | 16/6/2026 | Open redirect vulnerability in Vanilla Forums before 2.0.17.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Target parameter to an unspecified component, a different vulnerability than CVE-2011-0526. |