Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
934 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 11% | 💥 Exploit | Jabber Software Foundation Jabber Server | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en el módulo C2S de Jabber 2.x servidor (Jabberd) permite a atacantes remotos causar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código de su elección mediante un nombre de usuario largo. | |
| Modificada | Media (5) | 1.6% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag. | |
| Modificada | Media (5) | 1.3% | — | PD9 Software Megabbs | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Yabb SE | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions. | |
| Modificada | Alta (10) | 2.8% | — | Yabb | 31/12/2004 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters. | |
| Modificada | Media (5) | 1.4% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 1.0% | — | Yabb | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable. | |
| Modificada | Alta (7.5) | 1.1% | — | PD9 Software Megabbs | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Yabb | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect. | |
| Modificada | Alta (7.5) | 2.1% | — | Yabb | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl. | |
| Modificada | Media (5) | 1.8% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration. | |
| Modificada | Alta (7.5) | 1.3% | — | PD9 Software Megabbs | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp. | |
| Modificada | Media (5) | 1.4% | 💥 Exploit | Yabb | 23/11/2004 | 16/6/2026 | Vulnerabilidad de inyección de SQL en post.php de YaBB SE 1.5.4 y 1.5.5 permite a atacantes remotos obtener el resumen digital (hash) de contraseñas. | |
| Modificada | Media (6.4) | 2.2% | 💥 Exploit | Yabb | 23/11/2004 | 16/6/2026 | Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter. | |
| Modificada | Alta (10) | 1.8% | 💥 Exploit | Yabb | 23/11/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php. | |
| Modificada | Media (5) | 2.7% | — | Yabbforumsoftware YET Another Bulletin Board | 23/11/2004 | 16/6/2026 | YaBB SP 1.3.1 muestra mensajes de erro diferentes cuando un usuario existe o no, lo que hace más fácil para atacantes remotos identificar usuarios válidos y llevar a cabo ataques de adivinación de contraseñas por fuerza bruta. | |
| Modificada | Media (5) | 2.4% | — | Jabberstudio JabberdJabberstudio Jadc2s | 21/9/2004 | 16/6/2026 | The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections. | |
| Modificada | Media (5) | 1.6% | — | Yabb SEAI | 25/8/2004 | 16/6/2026 | YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message. | |
| Modificada | Media (5) | 1.5% | — | Yabb | 3/5/2004 | 16/6/2026 | Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Simple Machines SMFYabb | 15/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags. | |
| Modificada | Media (5) | 1.8% | — | Jabber Software Foundation Jabber Server | 3/2/2004 | 16/6/2026 | jabber 1.4.3, 1.4.2a, y posiblemente otras versiones no maneja apropiadamente conexiones SSL, lo que permite que atacantes remotos provoquen una denegación de servicio (caída). | |
| Modificada | Media (5) | 1.2% | — | Gabber | 31/12/2003 | 16/6/2026 | Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing. | |
| Modificada | Media (4.3) | 1.3% | — | Yabb | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject… | |
| Modificada | Media (5.1) | 1.1% | — | Yabb | 16/6/2003 | 16/6/2026 | SSI.php en YaBB SE 1.5.2 permite que atacantes remotos ejecuten código PHP arbitrario modificando el parámetro "sourcedir" para referenciar una URL en un servidor web remoto que contiene el código. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Yabb | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter. |