Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Power Board | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (5) | 1.2% | — | Mybulletinboard | 7/3/2006 | 16/6/2026 | SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Woltlab Burning Board | 7/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (4.3) | 0.94% | — | Ukiweb Ukiboard | 7/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which… | |
| Modificada | Alta (10) | 3.4% | 💥 Exploit | G2soft Pentacle In-out Board | 6/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Mybulletinboard | 2/3/2006 | 16/6/2026 | SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected. | |
| Modificada | Media (5) | 1.4% | — | Invision Power Services Invision Power Board | 28/2/2006 | 16/6/2026 | Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4)… | |
| Modificada | Media (5) | 1.3% | — | Invision Power Services Invision Power Board | 28/2/2006 | 16/6/2026 | Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6)… | |
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Jgs-xa Jgs-gallery AddonWoltlab Burning Board | 28/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid… | |
| Modificada | Baja (2.6) | 8.5% | 💥 Exploit | Invision Power Services Invision Power Board | 25/2/2006 | 16/6/2026 | index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users. | |
| Modificada | Alta (7.5) | 2.6% | — | Skate Board | 21/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php. | |
| Modificada | Media (4.3) | 1.4% | — | Skate Board | 21/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form. | |
| Modificada | Baja (3.5) | 1.1% | — | Skate Board | 21/2/2006 | 16/6/2026 | Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection. | |
| Modificada | Baja (2.6) | 1.2% | — | Mybulletinboard | 18/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details". NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (6.5) | 1.2% | — | Mybulletinboard | 10/2/2006 | 16/6/2026 | SQL injection vulnerability in moderation.php in MyBB (aka MyBulletinBoard) 1.0.3 allows remote authenticated users, with certain privileges for moderating and merging posts, to execute arbitrary SQL commands via the posts parameter. | |
| Modificada | Media (6.4) | 1.2% | — | Invisionpower Invision Power Board | 10/2/2006 | 16/6/2026 | The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password… | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 10/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E. | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard | 2/2/2006 | 16/6/2026 | SQL injection vulnerability in global.php in MyBB before 1.03 allows remote attackers to execute arbitrary SQL commands via the templatelist variable. | |
| Modificada | Media (4.3) | 0.36% | — | BlackboardBlackboard Academic Suite | 1/2/2006 | 16/6/2026 | Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their… | |
| Modificada | Media (4.3) | 1.2% | — | Yourboard Rlink | 1/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in rlink.php in Rlink 1.0.0 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Mybulletinboard | 1/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable). | |
| Modificada | Media (4.3) | 0.38% | — | Mybulletinboard | 1/2/2006 | 16/6/2026 | Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.02 allows local users with MyBB administrative privileges to include and possibly execute arbitrary local files via directory traversal sequences and a nul (%00) character in the plugin parameter. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Mybulletinboard | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Azbb AZ Bulletin Board | 25/1/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en post.php en AZ Bulletin Board (AZbb) 1.1.00 y anteriores permiten a atacantes remotos inyectar 'script' web arbitrario o HTML mediante el parámetro (1) "nickname" y la etiqueta (2) "iframe" en el parámetro "topic". NOTA: la información original… | |
| Modificada | Media (5) | 1.5% | — | Mybulletinboard | 25/1/2006 | 16/6/2026 | search.php en MyBB 1.0.2 permite a atacantes remotos obtener información sensible mediante una cierta petición de búsqueda que revela el prefijo de tabla en un mensaje de error SQL, posiblemente debido a parámetros no válidos.º |