Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Mybulletinboard | 22/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by… | |
| Modificada | Media (4.3) | 1.4% | — | Netbula Anyboard | 18/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in anyboard.cgi in Netbula Anyboard 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tK parameter in a find command. | |
| Modificada | Alta (7.5) | 1.0% | — | Mybulletinboard | 16/1/2006 | 16/6/2026 | The original distribution of MyBulletinBoard (MyBB) to update from older versions to 1.0.2 omits or includes older versions of certain critical files, which allows attackers to conduct (1) SQL injection attacks via an attachment name that is not properly handled by inc/functions_upload.php (CVE-2005-4602), and… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Venom Board | 10/1/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en add_post.php3 en Venom Board 1.22 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de los parámetros (1) parent, (2) root y (3) topic_id para post.php3. | |
| Modificada | Media (4.3) | 1.4% | — | Navboard | 9/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in post.php in NavBoard V16 Stable(2.6.0) and V17beta2 allows remote attackers to inject arbitrary web script or HTML via the (1) b, (2) textlarge, and (3) url bbcode tags. | |
| Modificada | Alta (7.5) | 1.4% | — | Oaboard | 5/1/2006 | 16/6/2026 | PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc_stat parameter, a different vulnerability than CVE-2006-0076. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Oaboard | 4/1/2006 | 16/6/2026 | PHP remote file include vulnerability in forum.php in oaBoard 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter. | |
| Modificada | Media (6.4) | 1.3% | — | Chitta Mimicboard | 31/12/2005 | 16/6/2026 | mimicboard2 (Mimic2) 086 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mimic2.dat. | |
| Modificada | Media (4.3) | 1.1% | — | Chitta Mimicboard 2 | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mimic2.cgi in mimicboard2 (Mimic2) 086 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters associated with the (1) name, (2) title, and (3) comment sections, as demonstrated by referencing a remote document through… | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread. | |
| Modificada | Media (5) | 1.2% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | Blackboard Learning and Community Portal System en Academic Suite 6.3.1.424, 6.2.3.32, y otras versiones anteriores a 6 permiten a atacantes remotos listar todas las categorías de variables mediante un parámetro "category_id" en blanco en category.pl. NOTA: no está claro si esta información es sensible o no, por lo… | |
| Modificada | Alta (7.5) | 1.5% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | Lo página de inicio de sesión en Blackboard Learning and Community Portal System en Academic Suite 6.3.1.424, 6.2.3.23, y otras versiones anteriores a 6 permiten a atacantes remotos saltarse la autenticación y ganar privilegios como otros usuarios mediante un parámetro "user_id" modificado y un "/" en el parámetro… | |
| Modificada | Media (4.3) | 0.95% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Blackboard Learning and Community Portal System en Academic Suite 6.3.1.424, 6.2.3.23, y otras versiones anteriores a la 6, permiten a atacantes remotos inyectar 'script' web o HTML de su elección mediante el parámetro "context" de announcemente.pl,… | |
| Modificada | Alta (10) | 2.7% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | announcement.pl en Blackboard Learning and Community Portal System en Academic Suite 6.3.1.424, 6.2.3.23, y otras versiones anteriores a 6 permiten a atacantes remotos ganar privilegios de administrador estableciendo el parámetro de contexto a "admin". | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Binary-concepts Binary Board System | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) board, and (6) stats.pl parameters to (b) stats.pl, and (7) board… | |
| Modificada | Media (4.3) | 1.2% | — | Bbboard | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bbBoard 2.56 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly via the "keys" parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Jamit JOB Board | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Jamit Job Board 2.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the vendor has disputed this issue, saying "The vulnerability is without any basis and did not actually work." CVE has not verified either the vendor or… | |
| Modificada | Alta (10) | 2.2% | — | Mybulletinboard | 13/12/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities than those identified by CVE-2005-4199. | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Blackboard Academic Suite | 13/12/2005 | 16/6/2026 | Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a… | |
| Modificada | Media (4.3) | 1.3% | — | ThwboardAI | 9/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to inject arbitrary web script or HTML via the (1) Wohnort and (2) Beruf fields in editprofile.php, (3) user parameter array in v_profile.php, and (4) the action parameter in misc.php. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Thwboard Beta | 9/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ThWboard before 3 Beta 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in calendar.php, (2) user parameter array in v_profile.php, and (3) the userid parameter in misc.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Sourceshock Shockboard | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |
| Modificada | Media (4.3) | 1.2% | — | ScssboardAI | 26/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search module in sCssBoard 1.2 and 1.12, and earlier versions, allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Mybulletinboard | 23/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.0 PR2 Rev 686 allow remote attackers to inject arbitrary web script or HTML via (1) the subject field when creating a new thread and (2) information passed to the Reputation system. | |
| Modificada | Media (5) | 1.3% | — | Mybulletinboard | 23/11/2005 | 16/6/2026 | MyBulletinBoard (MyBB) 1.0 PR2 Rev 686 allows remote attackers to delete or move private messages (PM) via modified fields in the inbox form. |