Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Elite-board Elite Bulletin Board | 12/1/2013 | 16/6/2026 | Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Elite Bulletin Board before 2.1.22 allow remote attackers to execute arbitrary SQL commands via the PATH_INFO to (a) checkuser.php, (b) groups.php, (c) index.php, (d) login.php, (e) quicklogin.php, (f)… | |
| Modificada | Media (5.8) | 1.5% | — | Vbulletin | 31/12/2012 | 16/6/2026 | Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Vbulletin | 28/8/2012 | 16/6/2026 | SQL injection vulnerability in announcement.php in vBulletin 4.1.10 allows remote attackers to execute arbitrary SQL commands via the announcementid parameter. | |
| Modificada | Alta (10) | 2.5% | — | Vbulletin MapiVbulletin ForumVbulletin Suite | 14/8/2012 | 16/6/2026 | Unspecified vulnerability in the MAPI in vBulletin Suite 4.1.2 through 4.1.12, Forum 4.1.2 through 4.1.12, and the MAPI plugin 1.4.3 for vBulletin 3.x has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Vbulletin | 3/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vBulletin 4.1.12 allows remote attackers to inject arbitrary web script or HTML via a long string in the subject parameter when creating a post. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mybulletinboard | 26/6/2009 | 16/6/2026 | SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Dream Radio AND TV Player Addon FOR Vbulletin | 23/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter. | |
| Modificada | Media (6.5) | 0.96% | — | Vbulletin | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in admincp/admincalendar.php in vBulletin 3.7.3.pl1 allows remote authenticated administrators to execute arbitrary SQL commands via the holidayinfo[recurring] parameter, a different vector than CVE-2005-3022. | |
| Modificada | Media (6.5) | 0.90% | — | Vbulletin | 24/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in vBulletin 3.7.4 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) answer parameter to admincp/verify.php, (2) extension parameter in an edit action to admincp/attachmentpermission.php, and the (3) iperm parameter to admincp/image.php. | |
| Modificada | Alta (7.5) | 1.1% | — | O2php Oxygen Bulletin Board | 28/10/2008 | 16/6/2026 | SQL injection vulnerability in member.php in Oxygen Bulletin Board 1.1.3 allows remote attackers to execute arbitrary SQL commands via the member parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vbulletin Vbgooglemap | 23/10/2008 | 16/6/2026 | SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Vbulletin | 22/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]). | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Vbulletin | 15/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Vbulletin | 17/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin Control Panel (admincp/index.php). | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Badongo Campus Bulletin Board | 28/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Campus Bulletin Board 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to post3/view.asp and the (2) review parameter to post3/book.asp. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Badongo Campus Bulletin Board | 28/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in post3/Book.asp in Campus Bulletin Board 3.4 allows remote attackers to inject arbitrary web script or HTML via the review parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Vbulletin | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action. | |
| Modificada | Media (6.5) | 1.4% | 💥 Exploit | Mybulletinboard | 15/2/2008 | 16/6/2026 | SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php. | |
| Modificada | Alta (7.5) | 42% | 💥 Exploit | Mybulletinboard | 22/1/2008 | 16/6/2026 | Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php. | |
| Modificada | Media (4.3) | 1.0% | — | Jelsoft Vbulletin | 21/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote attackers to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (a) faq.php, (b) member.php, (c) memberlist.php, (d) calendar.php, (e) search.php, (f) forumdisplay.php, (g)… | |
| Modificada | Alta (9.3) | 2.1% | — | Jelsoft Vbulletin | 1/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) specialtemplates parameter to… | |
| Modificada | Media (6.5) | 1.1% | — | Elite Bulletin Board | 6/7/2007 | 16/6/2026 | PM.php in Elite Bulletin Board before 1.0.10 allows remote authenticated users to delete arbitrary PM messages and conduct other attacks via modified id fields. | |
| Modificada | Media (5) | 1.2% | — | Elite Bulletin Board | 6/7/2007 | 16/6/2026 | Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks. | |
| Modificada | Media (5.8) | 1.2% | — | Jelsoft Vbulletin | 21/6/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and… | |
| Modificada | Baja (3.5) | 0.69% | — | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update. |