Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Ezboard | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument. | |
| Modificada | Media (5) | 2.7% | — | Yabbforumsoftware YET Another Bulletin Board | 23/11/2004 | 16/6/2026 | YaBB SP 1.3.1 muestra mensajes de erro diferentes cuando un usuario existe o no, lo que hace más fácil para atacantes remotos identificar usuarios válidos y llevar a cabo ataques de adivinación de contraseñas por fuerza bruta. | |
| Modificada | Media (5) | 1.7% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message. | |
| Modificada | Alta (10) | 2.4% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Open Bulletin Board Openbulletin BoardAI | 25/4/2004 | 16/6/2026 | The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript. | |
| Modificada | Alta (7.5) | 1.4% | — | Invision Power Services Invision Board | 3/1/2004 | 16/6/2026 | SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable. | |
| Modificada | Media (5) | 1.2% | — | Invision Power Services Invision Board | 31/12/2003 | 16/6/2026 | Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | PHP Board | 31/12/2003 | 16/6/2026 | login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Media (4.3) | 1.9% | — | Matt Wright WwwboardAI | 31/12/2003 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Tritanium Scripts Tritanium Bulletin Board | 31/12/2003 | 16/6/2026 | index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Versatilebulletinboard | 31/12/2003 | 16/6/2026 | activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid. | |
| Modificada | Media (6.8) | 4.0% | 💥 Exploit | Invision Power Services Invision Power Board | 31/12/2003 | 16/6/2026 | ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 1.3% | — | Vienuke VieboardAI | 23/11/2003 | 16/6/2026 | SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Vienuke Vieboard | 3/11/2003 | 16/6/2026 | SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Thwboard | 3/11/2003 | 16/6/2026 | Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php. | |
| Modificada | Media (4.3) | 1.8% | — | ThwboardAI | 3/11/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs." | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Ikonboard.com Ikonboard | 22/9/2003 | 16/6/2026 | FUNC.pm en IkonBoard 3.1.2a y anteriores, incluyendo 3.1.1, no limpia adecuadamente la galletita (cookie) "lang" cuando contiene caractéres ilegales, lo que permite a atacantes remotos ejecutar código arbitrario cuando la galletita se inserta en una sentencia Perl "eval". | |
| Modificada | Media (6.9) | 0.56% | — | Infopop Ultimate Bulletin Board | 18/8/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Infopop Ultimate Bulletin Board (UBB) 6.x permite a usuarios remotos autenticados ejecutar script web arbitrario y ganar acceso administrativo mediante el atributo "displayed name" de la galletita "ubber". | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Myupb Ultimate PHP Board | 2/7/2003 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9 permite a atacantes remotos ejecutar código PHP arbitrario con privilegios de administrador UPB mediante una petición HTTP conteniendo el código en la cabecera User-Agent, que es ejecutado cuando el administrador ejecuta admin_iplog.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Woltlab Burning Board | 2/4/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en board.php de WoltLab Burning Board (wBB) 2.0 RC1 y anteriores permite a atacantes remotos modificar la base de datos y posiblemente ganar privilegios mediante el parámetro boardid. | |
| Modificada | Media (5) | 1.2% | — | APP Apboard | 31/12/2002 | 16/6/2026 | The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter. | |
| Modificada | Media (5) | 1.4% | — | Powerboards | 31/12/2002 | 16/6/2026 | Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message. | |
| Modificada | Media (5) | 1.4% | — | Ultimate PHP Board | 31/12/2002 | 16/6/2026 | Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Zeroboard | 31/12/2002 | 16/6/2026 | Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.3) | 1.1% | — | Ikonboard | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header. |