Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | — | Betaboard | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user's profile, possibly using the FormVal_profile parameter. NOTE: it is not clear whether this is a distributable product or a site-specific vulnerability. If it is… | |
| Modificada | Media (4.3) | 0.94% | — | Revoboard | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation. NOTE: it is not clear whether… | |
| Modificada | Baja (2.6) | 1.2% | — | Tritanium Scripts Tritanium Bulletin Board | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_realname and (2) newuser_icq parameters, a different vector than CVE-2006-1768. NOTE: the provenance of this information is… | |
| Modificada | Media (5.1) | 2.3% | 💥 Exploit | Tritanium Scripts Tritanium Bulletin Board | 13/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php. | |
| Modificada | Media (5.1) | 1.5% | — | Mybulletinboard | 11/4/2006 | 16/6/2026 | Vulnerabilidad de XSS en inc/functions_post.php en MyBB (también conocido como MyBulletinBoard) 1.10 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un evento JavaScript en una etiqueta BBCode img. NOTA: el vector de correo electrónico ya esta cubierto par la… | |
| Modificada | Media (5.1) | 1.3% | — | Mybulletinboard | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username. | |
| Modificada | Media (6.8) | 1.4% | — | Mybulletinboard | 5/4/2006 | 16/6/2026 | Vulnerabilidad de XSS en inc/functions_post.php en MyBB (también conocido como MyBulletinBoard) 1.10 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un evento JavaScript en una etiqueta de correo electrónico BBCode, como se demuestra usando el evento onmousemove. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Media (4.3) | 1.2% | — | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.3% | — | Invision Power Services Invision Power Board | 23/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances. | |
| Modificada | Media (5) | 1.2% | — | Mybulletinboard | 22/3/2006 | 16/6/2026 | polls.php in MyBB (aka MyBulletinBoard) 1.10 allows remote attackers to obtain sensitive information via a vote action with an "option[]=null" parameter value, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Woltlab Burning Board | 21/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in acp/lib/class_db_mysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision Power Board | 21/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1;… | |
| Modificada | Media (5.8) | 1.1% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer. | |
| Modificada | Alta (7.5) | 1.2% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and… | |
| Modificada | Media (4.3) | 1.4% | — | Mybulletinboard | 19/3/2006 | 16/6/2026 | CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages. | |
| Modificada | Baja (3.5) | 1.4% | — | Mybulletinboard | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be vulnerable. | |
| Modificada | Media (5.1) | 1.2% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request. | |
| Modificada | Media (4.3) | 2.1% | — | Mybulletinboard | 19/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in member.php in MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, or (4) website field. | |
| Modificada | Media (4.3) | 1.8% | — | Zeroboard | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Woltlab Burning Board | 14/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS. | |
| Modificada | Media (5.1) | 1.6% | — | Jason Smith Cyboards PHP Lite | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php. | |
| Modificada | Media (4.3) | 1.9% | — | Ekinboard | 10/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EKINboard 1.0.3 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag. | |
| Modificada | Alta (7.5) | 2.0% | — | Ekinboard | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in config.php in EKINboard 1.0.3 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username cookie. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Datenbank ModuleWoltlab Burning Board | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php. |