Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitInvision Power Services Invision Power Board9/3/200616/6/2026
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.
ModificadaMedia (5)1.2%—Mybulletinboard7/3/200616/6/2026
SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter.
ModificadaMedia (4.3)1.4%💥 ExploitWoltlab Burning Board7/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (4.3)0.94%—Ukiweb Ukiboard7/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which…
ModificadaAlta (10)3.4%💥 ExploitG2soft Pentacle In-out Board6/3/200616/6/2026
Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.
ModificadaAlta (7.5)3.8%💥 ExploitMybulletinboard2/3/200616/6/2026
SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected.
ModificadaMedia (5)1.4%—Invision Power Services Invision Power Board28/2/200616/6/2026
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4)…
ModificadaMedia (5)1.3%—Invision Power Services Invision Power Board28/2/200616/6/2026
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6)…
ModificadaBaja (2.6)2.1%💥 ExploitJgs-xa Jgs-gallery AddonWoltlab Burning Board28/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid…
ModificadaBaja (2.6)8.5%💥 ExploitInvision Power Services Invision Power Board25/2/200616/6/2026
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.
ModificadaAlta (7.5)2.6%—Skate Board21/2/200616/6/2026
Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php.
ModificadaMedia (4.3)1.4%—Skate Board21/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.
ModificadaBaja (3.5)1.1%—Skate Board21/2/200616/6/2026
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.
ModificadaBaja (2.6)1.2%—Mybulletinboard18/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details". NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaMedia (6.5)1.2%—Mybulletinboard10/2/200616/6/2026
SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter.
ModificadaMedia (6.4)1.2%—Invisionpower Invision Power Board10/2/200616/6/2026
The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password…
ModificadaMedia (4.3)1.3%—Mybulletinboard10/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E.
ModificadaAlta (7.5)1.2%—Mybulletinboard2/2/200616/6/2026
SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable.
ModificadaMedia (4.3)0.36%—BlackboardBlackboard Academic Suite1/2/200616/6/2026
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their…
ModificadaMedia (4.3)1.2%—Yourboard Rlink1/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.2%—Mybulletinboard1/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).
ModificadaMedia (4.3)0.38%—Mybulletinboard1/2/200616/6/2026
Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter.
ModificadaMedia (4.3)2.5%💥 ExploitMybulletinboard31/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.
ModificadaMedia (4.3)2.6%💥 ExploitAzbb AZ Bulletin Board25/1/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en post.php en AZ Bulletin Board (AZbb) 1.1.00 y anteriores permiten a atacantes remotos inyectar 'script' web arbitrario o HTML mediante el parámetro (1) "nickname" y la etiqueta (2) "iframe" en el parámetro "topic". NOTA: la información original…
ModificadaMedia (5)1.5%—Mybulletinboard25/1/200616/6/2026
search.php en MyBB 1.0.2 permite a atacantes remotos obtener información sensible mediante una cierta petición de búsqueda que revela el prefijo de tabla en un mensaje de error SQL, posiblemente debido a parámetros no válidos.º