CVE Tools

Torrentflux

13 CVEs tracked since 2006. Since Oct 2006, none of them reached CISA KEV.

Torrentflux CVEs per month

Oct 2006 to Apr 2009. Point at a month, or focus the strip and use the arrow keys.
Torrentflux CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2006-1030
2006-11null or fewer
2006-1280
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-11null or fewer
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-0420

Products

The products that kept showing up in Torrentflux's monthly top three, with their CVEs summed over those months.

  1. Torrentflux133 months
  2. Torrentflux-b4rt11 month

Latest CVEs

The 13 most recently published vulnerabilities affecting Torrentflux.

  1. CVE-2008-6584html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extension in the url_upload parameter, which is download...6.0
  2. CVE-2008-6585Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via th...6.8
  3. CVE-2006-6604Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read arbitrary files via .. (dot dot) sequences in the alias parameter, a different ...6.5
  4. CVE-2006-6599maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.6.0
  5. CVE-2006-6600Cross-site scripting (XSS) vulnerability in dir.php in TorrentFlux 2.2, when allows remote attackers to inject arbitrary web script or HTML via double URL-encoded strings in the dir parameter, a re...6.0
  6. CVE-2006-6598Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-972 allows remote authenticated users to read arbitrary files via .. (dot dot...6.5
  7. CVE-2006-6328Directory traversal vulnerability in index.php for TorrentFlux 2.2 allows remote attackers to create or overwrite arbitrary files via sequences in the alias_file parameter.4.9
  8. CVE-2006-6329index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile parameter.4.9
  9. CVE-2006-6331metaInfo.php in TorrentFlux 2.2, when $cfg["enable_file_priority"] is false, allows remote attackers to execute arbitrary commands via shell metacharacters (backticks) in the torrent parameter to (...6.0
  10. CVE-2006-6330index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in the kill parameter.6.0
  11. CVE-2006-5609Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.5.0
  12. CVE-2006-5451Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) file, and (3) users array variables in (...2.6
  13. CVE-2006-5227Cross-site scripting (XSS) vulnerability in admin.php in TorrentFlux 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the $user_agent variable, probably obtained from the ...6.8

The record

Peak rank
#12 in Dec 2006
Busiest month shown
Dec 2006, 8 CVEs
Months with a KEV entry
0 since Oct 2006
Monthly snapshots
3 since 2006
Torrentflux's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store