Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.1% | — | Mybulletinboard | 25/5/2006 | 16/6/2026 | SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. NOTE: it is not clear from the original report how this attack can succeed, since the demonstration URL uses a variable that is overwritten with static data in… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | 4R LinklistWoltlab Burning Board | 24/5/2006 | 16/6/2026 | SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Azboard | 22/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in mono AZBOARD 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search and (2) cate parameters to (a) list.asp, and the (3) id and cate parameters to (b) admin_ok.asp. | |
| Modificada | Media (6.4) | 1.8% | — | Invision Power Services Invision Power Board | 20/5/2006 | 16/6/2026 | Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php. | |
| Modificada | Baja (2.6) | 2.3% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is… | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to… | |
| Modificada | Media (6.4) | 1.2% | — | Mybulletinboard | 12/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) 1.1.1 allow remote attackers to execute arbitrary SQL commands via the e-mail address when registering for a forum that requires e-mail verification, which is not properly handled in (1) usercp.php and (2) member.php. | |
| Modificada | Media (6.4) | 1.1% | 💥 Exploit | Mybulletinboard | 12/5/2006 | 16/6/2026 | SQL injection vulnerability in showthread.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary SQL commands via the comma parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Invision Power Services Invision Power Board | 5/5/2006 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5.5) | 1.1% | — | Invision Power Services Invision Power Board | 5/5/2006 | 16/6/2026 | SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. | |
| Modificada | Media (5) | 1.4% | — | Devsyn Open Bulletin Board | 5/5/2006 | 16/6/2026 | Open Bulletin Board (OpenBB) 1.0.8 allows remote attackers to obtain the full path of the web server via an invalid pforums parameter to (1) misc.php and (2) member.php. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Jsboard | 2/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using… | |
| Modificada | Media (4.3) | 1.1% | — | Devsyn Open Bulletin Board | 29/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and… | |
| Modificada | Baja (2.1) | 1.00% | — | Mybulletinboard | 29/4/2006 | 16/6/2026 | SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfunctions.php; or (2) setid, (3) expand, (4) title, or (5) sid2… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Invision Power Services Invision Power Board | 29/4/2006 | 16/6/2026 | SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM). | |
| Modificada | Media (6.4) | 2.2% | — | Invision Power Services Invision Power Board | 26/4/2006 | 16/6/2026 | Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to… | |
| Modificada | Media (5) | 1.6% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 26/4/2006 | 16/6/2026 | SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Invision Power Services Invision Power Board | 26/4/2006 | 16/6/2026 | action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Thwboard | 26/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mybulletinboard | 21/4/2006 | 16/6/2026 | SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter. | |
| Modificada | Baja (2.6) | 0.90% | — | Geekforgod.net Prayer Request Board | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field. | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | Thwboard | 20/4/2006 | 16/6/2026 | SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter. | |
| Modificada | Media (5.8) | 1.6% | 💥 Exploit | Mybulletinboard | 20/4/2006 | 16/6/2026 | MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks. | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyBB (MyBulletinBoard) 1.1 allows remote attackers to inject arbitrary web script or HTML via the attachment content disposition in an HTML attachment. | |
| Modificada | Media (5.8) | 1.4% | — | Script-solution.de Boardsolution | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Search for" item (keyword parameter). |