Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

934 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)11%💥 ExploitJabber Software Foundation Jabber Server10/1/200516/6/2026
Desbordamiento de búfer en el módulo C2S de Jabber 2.x servidor (Jabberd) permite a atacantes remotos causar una denegación de servicio (caída de aplicación) o posiblemente ejecutar código de su elección mediante un nombre de usuario largo.
ModificadaMedia (5)1.6%—Jabberstudio Jabber Gadu-gadu Transport31/12/200416/6/2026
Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag.
ModificadaMedia (5)1.3%—PD9 Software Megabbs31/12/200416/6/2026
CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp.
ModificadaAlta (7.5)2.4%💥 ExploitYabb SE31/12/200416/6/2026
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (1) recentTopics and (2) welcome functions.
ModificadaAlta (10)2.8%—Yabb31/12/200416/6/2026
Cross-site request forgery (CSRF) vulnerability in YaBB 1 GOLD SP 1.3.2 allows remote attackers to perform unauthorized actions as the administrative user via a link or IMG tag to YaBB.pl that specifies the desired action, id, and moda parameters.
ModificadaMedia (5)1.4%—Jabberstudio Jabber Gadu-gadu Transport31/12/200416/6/2026
The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors.
ModificadaMedia (5)1.0%—Yabb31/12/200416/6/2026
CRLF injection vulnerability in YaBB 1 Gold before 1.3.2 allows remote attackers to modify text file contents via the subject variable.
ModificadaAlta (7.5)1.1%—PD9 Software Megabbs31/12/200416/6/2026
Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.
ModificadaMedia (4.3)1.3%—Yabb31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in YaBB.pl in YaBB 1 GOLD SP 1.3.2 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded to parameter. NOTE: some sources say that the board parameter is affected, but this is incorrect.
ModificadaAlta (7.5)2.1%—Yabb31/12/200416/6/2026
Unknown vulnerability in Adminedit.pl YaBB 1 Gold before 1.3.2 allows attackers to execute arbitrary code via settings.pl.
ModificadaMedia (5)1.8%—Jabberstudio Jabber Gadu-gadu Transport31/12/200416/6/2026
Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration.
ModificadaAlta (7.5)1.3%—PD9 Software Megabbs31/12/200416/6/2026
SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memberid or (4) teamid parameter to view-profile.asp.
ModificadaMedia (5)1.4%💥 ExploitYabb23/11/200416/6/2026
Vulnerabilidad de inyección de SQL en post.php de YaBB SE 1.5.4 y 1.5.5 permite a atacantes remotos obtener el resumen digital (hash) de contraseñas.
ModificadaMedia (6.4)2.2%💥 ExploitYabb23/11/200416/6/2026
Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.
ModificadaAlta (10)1.8%💥 ExploitYabb23/11/200416/6/2026
Multiple SQL injection vulnerabilities in YaBB SE 1.5.4 through 1.5.5b allow remote attackers to execute arbitrary SQL via (1) the msg parameter in ModifyMessage.php or (2) the postid parameter in ModifyMessage.php.
ModificadaMedia (5)2.7%—Yabbforumsoftware YET Another Bulletin Board23/11/200416/6/2026
YaBB SP 1.3.1 muestra mensajes de erro diferentes cuando un usuario existe o no, lo que hace más fácil para atacantes remotos identificar usuarios válidos y llevar a cabo ataques de adivinación de contraseñas por fuerza bruta.
ModificadaMedia (5)2.4%—Jabberstudio JabberdJabberstudio Jadc2s21/9/200416/6/2026
The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections.
ModificadaMedia (5)1.6%—Yabb SEAI25/8/200416/6/2026
YaBB SE 1.5.1 allows remote attackers to obtain sensitive information via a direct HTTP request to Admin.php, which reveals the full path in a PHP error message.
ModificadaMedia (5)1.5%—Yabb3/5/200416/6/2026
Post.pl in YaBB 1 Gold SP 1.2 allows remote attackers to modify records in the board's .txt file via carriage return characters in the subject field.
ModificadaMedia (4.3)2.1%💥 ExploitSimple Machines SMFYabb15/3/200416/6/2026
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
ModificadaMedia (5)1.8%—Jabber Software Foundation Jabber Server3/2/200416/6/2026
jabber 1.4.3, 1.4.2a, y posiblemente otras versiones no maneja apropiadamente conexiones SSL, lo que permite que atacantes remotos provoquen una denegación de servicio (caída).
ModificadaMedia (5)1.2%—Gabber31/12/200316/6/2026
Gabber 0.8.7 sends an email to a specific address during user login and logout, which allows remote attackers to obtain user session activity and Gabber version number by sniffing.
ModificadaMedia (4.3)1.3%—Yabb31/12/200316/6/2026
Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject…
ModificadaMedia (5.1)1.1%—Yabb16/6/200316/6/2026
SSI.php en YaBB SE 1.5.2 permite que atacantes remotos ejecuten código PHP arbitrario modificando el parámetro "sourcedir" para referenciar una URL en un servidor web remoto que contiene el código.
ModificadaMedia (4.3)3.9%💥 ExploitYabb31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter.
Orbitaley — Vulnerabilidades