Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Vbulletin Vbgooglemap | 23/10/2008 | 16/6/2026 | SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Vbulletin | 22/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]). | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Vbulletin | 15/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Vbulletin | 17/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin Control Panel (admincp/index.php). | |
| Modificada | Alta (7.5) | 1.1% | — | Vbulletin | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in faq.php in vBulletin 3.7.0 Gold allows remote attackers to execute arbitrary SQL commands via the q parameter in a search action. | |
| Modificada | Media (4.3) | 1.0% | — | Jelsoft Vbulletin | 21/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote attackers to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (a) faq.php, (b) member.php, (c) memberlist.php, (d) calendar.php, (e) search.php, (f) forumdisplay.php, (g)… | |
| Modificada | Alta (9.3) | 2.1% | — | Jelsoft Vbulletin | 1/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) specialtemplates parameter to… | |
| Modificada | Media (5.8) | 1.2% | — | Jelsoft Vbulletin | 21/6/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and… | |
| Modificada | Alta (8.5) | 1.3% | — | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related issue to CVE-2007-1573. | |
| Modificada | Media (5) | 1.2% | — | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction "red flag" for a deleted user. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action. | |
| Modificada | Media (4.3) | 0.84% | — | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a related issue to CVE-2007-2909. | |
| Modificada | Baja (3.5) | 0.69% | — | Jelsoft Vbulletin | 30/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_calendar366_xss_fix_plugin.xml update. | |
| Modificada | Media (6) | 0.90% | — | Jelsoft Vbulletin | 21/3/2007 | 16/6/2026 | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field. | |
| Modificada | Media (4.3) | 1.1% | — | Jelsoft Vbulletin | 8/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Jelsoft Vbulletin | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. NOTE: the vendor states that the attack is feasible only in circumstances "almost impossible to… | |
| Modificada | Media (4.3) | 1.1% | — | Jelsoft Vbulletin | 9/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field. NOTE: this might be a duplicate of CVE-2007-0830.5. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Baja (3.5) | 0.91% | — | Jelsoft Vbulletin | 7/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code… | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | Jelsoft Vbulletin | 28/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Jelsoft Vbulletin | 22/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Jelsoft Vbulletin | 3/10/2006 | 16/6/2026 | SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Jelsoft Vbulletin | 21/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6. | |
| Modificada | Alta (7.5) | 2.1% | — | Jelsoft Vbulletin | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this vulnerability, saying "The default vBulletin requires authentication prior to the usage of the upgrade… | |
| Modificada | Alta (7.5) | 1.5% | — | Jelsoft Vbulletin | 21/8/2006 | 16/6/2026 | Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go… | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Jelsoft Vbulletin | 28/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering… |