Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 87 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mybulletinboard | 16/8/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php. | |
| Modificada | Media (5) | 1.2% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9)… | |
| Modificada | Alta (7.5) | 5.1% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file. | |
| Modificada | Media (4.3) | 1.3% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Invision Power Services Invision Board | 10/8/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML. | |
| Modificada | Media (4.3) | 1.3% | — | Seo-board | 20/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en smilies_popup.php en SEO-Board 1.0 permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "doc". | |
| Modificada | Media (4.3) | 1.4% | — | Simple Message BoardAI | 19/7/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados en Simple Message Board Version 2.0 Beta 1 permite que atacantes remtos inyecten script web arbitrario o HTML mediante 1) el parámetro FID en "forum.cfm", 2) el parámetro UID en "user.cfm", 3) el parámetro TID en "thread.cfm" o 4) el parámetro… | |
| Modificada | Alta (7.5) | 1.3% | — | ID Board | 11/7/2005 | 16/6/2026 | SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Fsboard | 5/7/2005 | 16/6/2026 | Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mercuryboard Message Board | 21/6/2005 | 16/6/2026 | SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | |
| Modificada | Media (5) | 1.2% | — | Ultimate PHP Board | 17/6/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ref parameter to login.php, (2) id or (3) page parameter to viewtopic.php, id parameter to (4) profile.php, (5) newpost.php, (6) email.php, (7)… | |
| Modificada | Media (5) | 1.2% | — | Ultimate PHP Board | 16/6/2005 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9.6 GOLD and earlier stores the users.dat file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information on registered users via a direct request to db/users.dat. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Ultimate PHP Board | 16/6/2005 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9.6 GOLD uses weak encryption for passwords in the users.dat file, which allows attackers to easily decrypt the passwords and gain privileges, possibly after exploiting CVE-2005-2005 to obtain users.dat. | |
| Modificada | Media (5) | 1.2% | — | Ultimate PHP Board | 16/6/2005 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Zeroboard | 1/6/2005 | 16/6/2026 | zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function. | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 1/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile. | |
| Modificada | Media (5) | 1.9% | 💥 Exploit | Invision Power Services Invision Board | 1/6/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters. | |
| Modificada | Media (4.6) | 0.50% | — | Invision Power Services Invision Board | 1/6/2005 | 16/6/2026 | Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen. | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 31/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut parameter to forumdisplay.php, (6) username, (7) email, or (8)… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Mybulletinboard | 31/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4) pid parameter to editpost.php, (5) fid parameter to… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Woltlab Burning Board | 17/5/2005 | 16/6/2026 | SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Ultimate PHP Board | 16/5/2005 | 16/6/2026 | viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to obtain sensitive information via an invalid (1) id or possibly (2) postorder parameter, which reveals the path in an error message when a file can not be opened. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. |