Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
–

1619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Mercuryboard Message Board23/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message).
ModificadaMedia (4.3)1.2%—Zeroboard19/2/200516/6/2026
Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.
ModificadaMedia (4.3)0.94%—Mercuryboard17/2/200516/6/2026
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
ModificadaMedia (5)1.4%—Mercuryboard25/1/200516/6/2026
MercuryBoard 1.1.1 allows remote attackers to gain sensitive information via an HTTP request with the n parameter set to 0, which causes a divide-by-zero error and reveals the path in the resulting error message.
ModificadaMedia (4.3)1.7%💥 ExploitMercuryboard25/1/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) s, (2) l, (3) a, (4) t, (5) to, or (6) re parameters.
ModificadaMedia (5)1.7%—Jsboard20/1/200516/6/2026
Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.
ModificadaAlta (7.5)1.3%—Gosmart Message Board31/12/200416/6/2026
SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.
ModificadaMedia (4.3)1.3%—Thwboard Beta31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in board.php for ThWboard before beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the lastvisited parameter.
ModificadaMedia (4.3)1.9%—Zeroboard31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in check_user_id.php in ZeroBoard 4.1pl4 and earlier allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.
ModificadaMedia (4.3)1.3%—Gosmart Message Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.
ModificadaAlta (7.5)1.3%💥 ExploitInvision Power Services Invision Board31/12/200416/6/2026
SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.
ModificadaAlta (7.5)1.9%💥 ExploitBroadboard Instant ASP Message Board31/12/200416/6/2026
Multiple SQL injection vulnerabilities in BroadBoard Instant ASP Message Board allow remote attackers to run arbitrary SQL commands via the (1) keywords parameter to search.asp, (2) handle parameter to profile.asp, (3) txtUserHandle parameter to reg2.asp or (4) txtUserEmail parameter to forgot.asp.
ModificadaMedia (5)2.6%—Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+1831/12/200416/6/2026
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
ModificadaAlta (7.5)2.4%💥 ExploitIkonboard.com Ikonboard31/12/200416/6/2026
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrary SQL commands via the (1) st or (2) keywords parameter.
ModificadaMedia (4.3)3.6%💥 ExploitAntiboard31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inject arbitrary HTML or web script via the feedback parameter.
ModificadaMedia (4.3)1.1%—Invision Power Services Invision Power Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.
ModificadaMedia (6.8)2.4%—Zeroboard31/12/200416/6/2026
PHP remote file inclusion vulnerability in ZeroBoard 4.1pl4 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) _zb_path parameter to outlogin.php or (2) dir parameter to write.php to reference a URL on a remote web server that contains the code.
ModificadaMedia (4.6)0.63%—TIM Mann Xboard31/12/200416/6/2026
Buffer overflow in XBoard 4.2.7 and earlier might allow local users to execute arbitrary code via a long -icshost command line argument. NOTE: since the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for the issue that crosses privilege boundaries.…
ModificadaAlta (9.3)6.6%💥 ExploitBoard Power31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaMedia (5)1.2%—Blackboard31/12/200416/6/2026
BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message.
ModificadaMedia (4.3)0.95%—Invision Power Services Invision Power Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
ModificadaAlta (7.5)1.7%—SIR Gnuboard31/12/200416/6/2026
PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.
ModificadaAlta (7.5)1.7%—Blackboard Internet Newsboard System31/12/200416/6/2026
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
ModificadaAlta (7.5)2.4%💥 ExploitAntiboard31/12/200416/6/2026
SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary SQL via the (1) thread_id, (2) parent_id, or (3) mode parameters.
ModificadaMedia (6.8)5.6%—Invision Power Services Invision Board23/11/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.