Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.0%💥 ExploitEzboard23/11/200416/6/2026
Cross-site scripting (XSS) vulnerability in the font tag in ezBoard 7.3u allows remote attackers to execute arbitrary script as other users, as demonstrated using the background:url in a (1) font color or (2) font face argument.
ModificadaMedia (5)2.7%—Yabbforumsoftware YET Another Bulletin Board23/11/200416/6/2026
YaBB SP 1.3.1 muestra mensajes de erro diferentes cuando un usuario existe o no, lo que hace más fácil para atacantes remotos identificar usuarios válidos y llevar a cabo ataques de adivinación de contraseñas por fuerza bruta.
ModificadaMedia (5)1.7%—Invision Power Services Invision Board23/11/200416/6/2026
Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message.
ModificadaAlta (10)2.4%—Invision Power Services Invision Board23/11/200416/6/2026
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.
ModificadaAlta (7.5)1.5%—Open Bulletin Board Openbulletin BoardAI25/4/200416/6/2026
The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.
ModificadaAlta (7.5)1.4%—Invision Power Services Invision Board3/1/200416/6/2026
SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable.
ModificadaMedia (5)1.2%—Invision Power Services Invision Board31/12/200316/6/2026
Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access.
ModificadaMedia (5.8)1.8%💥 ExploitPHP Board31/12/200316/6/2026
login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information via a direct request.
ModificadaMedia (4.3)1.9%—Matt Wright WwwboardAI31/12/200316/6/2026
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.
ModificadaMedia (5)2.9%💥 ExploitTritanium Scripts Tritanium Bulletin Board31/12/200316/6/2026
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying the thread_id, forum_id, and sid parameters.
ModificadaAlta (7.5)1.5%—Versatilebulletinboard31/12/200316/6/2026
activate.php in versatileBulletinBoard (vBB) 0.9.5 and 0.9.6 allows remote attackers to gain unauthorized administrative access via a URL request with the uid parameter set to the webmaster uid.
ModificadaMedia (6.8)4.0%💥 ExploitInvision Power Services Invision Power Board31/12/200316/6/2026
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
ModificadaAlta (7.5)1.3%—Vienuke VieboardAI23/11/200316/6/2026
SQL injection vulnerability in getmember.asp in VieBoard 2.6 Beta 1 allows remote attackers to execute arbitrary SQL commands via the msn variable.
ModificadaAlta (7.5)1.2%💥 ExploitVienuke Vieboard3/11/200316/6/2026
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
ModificadaAlta (7.5)1.4%—Thwboard3/11/200316/6/2026
Multiple SQL injection vulnerabilities in ThWboard before Beta 2.8.2 allow remote attackers to inject arbitrary SQL commands via various vectors including (1) Admin-Center, (2) Announcements, (3) admin/calendar.php, and (4) showevent.php.
ModificadaMedia (4.3)1.8%—ThwboardAI3/11/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."
ModificadaAlta (7.5)11%💥 ExploitIkonboard.com Ikonboard22/9/200316/6/2026
FUNC.pm en IkonBoard 3.1.2a y anteriores, incluyendo 3.1.1, no limpia adecuadamente la galletita (cookie) "lang" cuando contiene caractéres ilegales, lo que permite a atacantes remotos ejecutar código arbitrario cuando la galletita se inserta en una sentencia Perl "eval".
ModificadaMedia (6.9)0.56%—Infopop Ultimate Bulletin Board18/8/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Infopop Ultimate Bulletin Board (UBB) 6.x permite a usuarios remotos autenticados ejecutar script web arbitrario y ganar acceso administrativo mediante el atributo "displayed name" de la galletita "ubber".
ModificadaAlta (7.5)2.5%💥 ExploitMyupb Ultimate PHP Board2/7/200316/6/2026
Ultimate PHP Board (UPB) 1.9 permite a atacantes remotos ejecutar código PHP arbitrario con privilegios de administrador UPB mediante una petición HTTP conteniendo el código en la cabecera User-Agent, que es ejecutado cuando el administrador ejecuta admin_iplog.php.
ModificadaAlta (7.5)2.4%💥 ExploitWoltlab Burning Board2/4/200316/6/2026
Vulnerabilidad de inyección de SQL en board.php de WoltLab Burning Board (wBB) 2.0 RC1 y anteriores permite a atacantes remotos modificar la base de datos y posiblemente ganar privilegios mediante el parámetro boardid.
ModificadaMedia (5)1.2%—APP Apboard31/12/200216/6/2026
The new thread posting page in APBoard 2.02 and 2.03 allows remote attackers to post messages to protected forums by modifying the insertinto parameter.
ModificadaMedia (5)1.4%—Powerboards31/12/200216/6/2026
Powerboards 2.2b allows remote attackers to view the full path to the backend database by sending a cookie containing a non-existent username to profiles.php, which displays the full path in the error message.
ModificadaMedia (5)1.4%—Ultimate PHP Board31/12/200216/6/2026
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.
ModificadaMedia (5)2.3%💥 ExploitZeroboard31/12/200216/6/2026
Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execute arbitrary PHP code by modifying the _zb_path parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (4.3)1.1%—Ikonboard31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Ikonboard 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL in a photo URL or (2) an X-Forwarded-For: header.