Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Apboard | 22/11/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en thread.php en APBoard permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro "start". | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Unclassified Newsboard | 19/11/2005 | 16/6/2026 | SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Ekinboard | 16/11/2005 | 16/6/2026 | Vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Ekinboard 1.0.3. permite a atacantes remotos inyectar script web de su elección mediante (1) el parámetro id en profile.php y (2) títulos de mensajes enviados. | |
| Modificada | Media (6.5) | 1.9% | — | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de inyección directa de código en Administrador de Tareas de Invision Power Board 2.0.1 permite a atacantes remotos limitados ejecutar código de su elección referenciando el fichero en el campo Task PHP File To Run y seleccionando Run Task Now. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Invision Power Board 2.1 permite a atacantes remotos inyectar web scritp o HTML de su elección mediante los parámetros (1) adsess, (2) name y (3) description en admin.php, y (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8)… | |
| Modificada | Media (4) | 1.3% | — | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de atravesammiento de directorios en Administrador de Tareas de Invision Power Board 2.0.1 (IP.Board) permite a atacantes remotos limitados incluir ficheros mediante un .. (punto punto) en el campo Task PHP File To Run. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Oaboard | 1/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module. | |
| Modificada | Alta (7.5) | 1.5% | — | Platinum Dboardgear | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Woltlab Burning BoardAI | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Mybulletinboard | 27/10/2005 | 16/6/2026 | SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in… | |
| Modificada | Media (5) | 1.6% | — | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | getversions.php in versatileBulletinBoard (vBB) 1.0.0 RC2 lists the versions of all installed scripts, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Media (4.3) | 1.4% | — | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter in dereferrer.php and (2) the file parameter in imagewin.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Seo-boardAI | 27/9/2005 | 16/6/2026 | SQL injection vulnerability in admin.php in SEO-Board 1.0.2 allows remote attackers to execute arbitrary SQL commands via the user_pass_sha1 value in a cookie. | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard MybbAI | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) Preview Release 2 allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter to misc.php or (2) Content-Disposition field in the HTTP header to newreply.php. | |
| Modificada | Media (4.3) | 0.95% | — | CJ Design CJ TAG Board | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Unclassified Newsboard | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field. | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard | 2/9/2005 | 16/6/2026 | SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Mybulletinboard | 26/8/2005 | 16/6/2026 | SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Phptb Topic Boards | 23/8/2005 | 16/6/2026 | Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and earlier allow remote attackers to execute arbitrary PHP code via the absolutepath parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Woltlab Burning Board | 23/8/2005 | 16/6/2026 | SQL injection vulnerability in modcp.php in WoltLab Burning Board 2.2.2 and 2.3.3 allows remote authenticated attackers to execute arbitrary SQL commands via the (1) x or (2) y parameters. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Funkboard | 16/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FunkBoard 0.66CF, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the fbusername or fbpassword parameter to (1) editpost.php, (2) prefs.php, (3) newtopic.php, (4) reply.php, or (5) profile.php, the (6) fbusername,… | |
| Modificada | Media (5) | 1.2% | — | Funkboard | 16/8/2005 | 16/6/2026 | FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to forums.php, which reveals the path in an error message. | |
| Modificada | Media (6.4) | 1.2% | — | Funkboard | 16/8/2005 | 16/6/2026 | FunkBoard 0.66CF, and possibly earlier versions, does not properly restrict access to the (1) admin/mysql_install.php and (2) admin/pg_install.php scripts, which allows attackers to obtain the database username and password or inject arbitrary PHP code into info.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Phptb Topic Boards | 16/8/2005 | 16/6/2026 | SQL injection vulnerability in emailvalidate.php in PHPTB Topic Boards 2.0 allows remote attackers to execute arbitrary SQL commands via the mid parameter. |