Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Mercuryboard Message Board | 23/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message). | |
| Modificada | Media (4.3) | 1.2% | — | Zeroboard | 19/2/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php. | |
| Modificada | Media (4.3) | 0.94% | — | Mercuryboard | 17/2/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter. | |
| Modificada | Media (5) | 1.4% | — | Mercuryboard | 25/1/2005 | 16/6/2026 | MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mercuryboard | 25/1/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters. | |
| Modificada | Media (5) | 1.7% | — | Jsboard | 20/1/2005 | 16/6/2026 | Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Gosmart Message Board | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Thwboard Beta | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Zeroboard | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Gosmart Message Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Invision Power Services Invision Board | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Broadboard Instant ASP Message Board | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp. | |
| Modificada | Media (5) | 2.6% | — | Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+18 | 31/12/2004 | 16/6/2026 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Ikonboard.com Ikonboard | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Antiboard | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Invision Power Services Invision Power Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header. | |
| Modificada | Media (6.8) | 2.4% | — | Zeroboard | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.6) | 0.63% | — | TIM Mann Xboard | 31/12/2004 | 16/6/2026 | Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries.… | |
| Modificada | Alta (9.3) | 6.6% | 💥 Exploit | Board Power | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Media (5) | 1.2% | — | Blackboard | 31/12/2004 | 16/6/2026 | BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message. | |
| Modificada | Media (4.3) | 0.95% | — | Invision Power Services Invision Power Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php. | |
| Modificada | Alta (7.5) | 1.7% | — | SIR Gnuboard | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 1.7% | — | Blackboard Internet Newsboard System | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Antiboard | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters. | |
| Modificada | Media (6.8) | 5.6% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters. |