Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Deluxebb | 11/8/2006 | 16/6/2026 | pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Deluxebb | 24/7/2006 | 16/6/2026 | DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user. | |
| Modificada | Alta (7.5) | 1.4% | — | Deluxebb | 24/7/2006 | 16/6/2026 | DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT." | |
| Modificada | Alta (7.5) | 1.4% | — | Deluxebb | 24/7/2006 | 16/6/2026 | SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (1) memberpw and (2) membercookie cookies. | |
| Modificada | Media (5) | 1.4% | — | Deluxebb | 24/7/2006 | 16/6/2026 | DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to multiple security vulnerabilities, aka "pollution of the global… | |
| Modificada | Baja (2.6) | 1.4% | — | Deluxebb | 24/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php. | |
| Modificada | Media (4.3) | 1.2% | — | Deluxebb | 29/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pm.php in DeluxeBB 1.07 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) to parameters. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Deluxebb | 29/6/2006 | 16/6/2026 | SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter. | |
| Modificada | Media (5.1) | 1.6% | — | Deluxebb | 23/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration. | |
| Modificada | Media (5.1) | 21% | 💥 Exploit | Deluxebb | 23/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Deluxebb | 22/5/2006 | 16/6/2026 | SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via the name parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Nmdeluxe | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Nmdeluxe | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in news.php in NMDeluxe before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the nick parameter. | |
| Modificada | Baja (2.6) | 1.6% | — | Smithmicro Stuffit DeluxeSmithmicro Stuffit ExpanderSmithmicro Stuffit StandardSmithmicro Zipmagic Deluxe | 28/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in Allume StuffIt Standard and Deluxe 9.0, ZipMagic Deluxe 9.0, and StuffIt Expander 9.0.0.21 Engine 9.0.0.21 allow remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a (1) zip or (2) tar archive. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Deluxebb | 20/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or (3) pm.php, or the fid parameter to (3) forums.php or (4) newpost.php. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Alta (7.2) | 0.87% | 💥 Exploit | Light Speed Technology Deluxeftp | 2/5/2005 | 16/6/2026 | Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 4.0% | — | Apache Http ServerUsanet Creations Makebid Auction Deluxe | 29/5/2002 | 16/6/2026 | Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3,… | |
| Modificada | Media (5.1) | 2.1% | — | Adobe Photodeluxe | 9/2/2002 | 16/6/2026 | The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page. |