Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
ModificadaMedia (5.4)0.63%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an…
ModificadaAlta (7.2)2.1%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
ModificadaAlta (7.8)0.45%—Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe19/2/202017/6/2026
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
ModificadaAlta (8.1)0.74%💥 PoCIdashboards18/2/201817/6/2026
An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials.
ModificadaAlta (7.5)1.5%—Idashboards18/2/201817/6/2026
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts.
ModificadaAlta (7.5)1.5%—Idashboards18/2/201817/6/2026
An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports.
ModificadaAlta (8.3)0.72%—Boosted Boards10/4/201517/6/2026
Unspecified vulnerability in Boosted Boards skateboards allows physically proximate attackers to modify skateboard movement, cause human injury, or cause physical damage via vectors related to an "injection attack" that blocks and hijacks a Bluetooth signal.
ModificadaAlta (7.5)1.00%💥 ExploitStormboards Aaronnemisis Stormboards26/12/200816/6/2026
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.4%—Hotscripts Cyboards PHP Lite19/8/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the script_path parameter to (1) flat_read.php, (2) post.php, (3) process_post.php, (4) process_search.php, (5) forum.php, (6) process_subscribe.php, (7) read.php, (8)…
ModificadaMedia (4.3)1.0%—Hotscripts Cyboards PHP Lite19/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to inject arbitrary web script or HTML via the (1) lOptionsOptions, (2) lNavAdminOptions, or (3) lNavReturn parameter to options.php; or the (4) lNavReturn parameter to subscribe.php.
ModificadaMedia (5.1)1.3%—Hotscripts Cyboards PHP Lite19/8/200816/6/2026
Multiple directory traversal vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) script_path parameter to (a) options.php and the (2) lang_code parameter to (b) copy_vip.php and (c) process_edit_board.php in…
ModificadaMedia (4.3)1.4%—National Rail Enquiries Live Departure Boards30/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject arbitrary web script or HTML, and execute arbitrary code, via a response body, as demonstrated by a SCRIPT element that…
ModificadaAlta (7.5)2.6%💥 ExploitConnectix Boards31/1/200816/6/2026
PHP remote file inclusion vulnerability in templates/Official/part_userprofile.php in Connectix Boards 0.8.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the template_path parameter.
ModificadaAlta (7.5)2.8%💥 ExploitCyboards PHP Lite12/4/200716/6/2026
PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter, a different vector than CVE-2006-2871.
ModificadaMedia (6.5)0.99%💥 ExploitConnectix Boards3/3/200716/6/2026
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.
ModificadaMedia (6)0.91%💥 ExploitConnectix Boards3/3/200716/6/2026
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticated administrators to execute arbitrary PHP code by uploading a crafted GIF smiley image with a .php extension via the uploadimage parameter to admin.php, which can be later accessed via a direct…
ModificadaAlta (7.5)3.2%💥 ExploitHailboards1/2/200716/6/2026
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
ModificadaMedia (5)1.6%—James Greenwood Monkey Boards28/11/200616/6/2026
Monkey Boards 0.3.5 allows remote attackers to obtain sensitive information via direct requests to (1) include/admin_auth.inc.php and (2) include/engine/class.compiler.php, which reveals the full path in an error message. NOTE: this issue is only an exposure if the administrator has changed the default script path.
ModificadaAlta (7.5)3.4%💥 ExploitCyboards PHP Lite6/6/200616/6/2026
PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. NOTE: CVE disputes this issue, since $script_path is set to a constant value
ModificadaMedia (5.8)1.4%—Script-solution.de Boardsolution20/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Search for" item (keyword parameter).
ModificadaMedia (5.1)1.6%—Jason Smith Cyboards PHP Lite10/3/200616/6/2026
SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php.
ModificadaAlta (7.5)2.9%💥 ExploitPhptb Topic Boards23/8/200516/6/2026
Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and earlier allow remote attackers to execute arbitrary PHP code via the absolutepath parameter.
ModificadaAlta (7.5)1.1%💥 ExploitPhptb Topic Boards16/8/200516/6/2026
SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter.
ModificadaMedia (5)1.4%—Powerboards31/12/200216/6/2026
Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message.
Orbitaley — Vulnerabilidades