Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | Ultimate PHP Board | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Ultimate PHP Board | 16/5/2005 | 16/6/2026 | viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability. | |
| Modificada | Media (5) | 1.8% | — | Colored Scripts Easy Message Board | 14/5/2005 | 16/6/2026 | Directory traversal vulnerability in easymsgb.pl in Easy Message Board allows remote attackers to read arbitrary files via a .. (dot dot) in the print parameter. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Colored Scripts Easy Message Board | 14/5/2005 | 16/6/2026 | easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Invisionpower Invision Power BoardAI | 3/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters. | |
| Modificada | Media (5) | 1.8% | — | Zeroboard | 2/5/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in ZeroBoard 4.1pl5 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the _zb_path parameter to (1) _head.php or (2) outlogin.php, or the dir parameter to (3) write.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | SIR Gnuboard | 2/5/2005 | 16/6/2026 | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters. | |
| Modificada | Media (4.3) | 0.94% | — | Mercuryboard | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field. | |
| Modificada | Alta (7.5) | 1.1% | — | Woltlab Burning Board | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or (2) lastvisit cookie. | |
| Modificada | Alta (10) | 1.7% | — | ScssboardAI | 2/5/2005 | 16/6/2026 | Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page." | |
| Modificada | Media (5) | 1.5% | — | Mercuryboard | 2/5/2005 | 16/6/2026 | index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Woltlab Burning Board LiteAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Azbb AZ Bulletin Board | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.3) | 1.2% | — | ScssboardAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags. | |
| Modificada | Media (4.3) | 0.99% | — | Woltlab Burning Board | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Invision Power Services Invision Board | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Infopop Ultimate Bulletin Board | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in printthread.php in UBB.Threads allows remote attackers to execute arbitrary SQL commands via the main parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Bitshifters Bitboard | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bitboard 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via an [img] bbcode image tag with an event such as mouseover. | |
| Modificada | Alta (7.5) | 1.8% | — | Mercuryboard | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary SQL commands via the f parameter. | |
| Modificada | Alta (7.5) | 4.4% | — | Zeroboard | 2/5/2005 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in (1) print_category.php, (2) login.php, (3) setup.php, (4) ask_password.php, or (5) error.php in ZeroBoard 4.1pl5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the dir parameter to reference a URL on a remote web server that contains… | |
| Modificada | Alta (7.5) | 2.1% | — | Mybulletinboard | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Mercuryboard | 27/4/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en post.php de MercuryBoard 1.1.1 permite a atacantes remotos ejecutar órdenes SQL arbitrarias mediante una acción de respuesta a envío (post) en index.php con (1) el parámetro t o (2) el parámetro qu. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Woltlab Burning Board | 22/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Board | 11/4/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision Power Board | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una etiqueta IMG en una etiqueta COLOR cuyo estilo está puesto como background:url. |