Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2861▲ 225 respecto a la semana anterior
Críticas / altas1331▼ 100 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Logitech Cordless FreedomLogitech Cordless Freedom NavigatorLogitech Cordless Freedom PROLogitech Cordless Itouch Keyboard18/10/200116/6/2026
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.
ModificadaMedia (5)5.2%💥 ExploitOreilly Webboard18/10/200116/6/2026
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.
ModificadaMedia (5)7.3%💥 ExploitSixhead Six-webboard13/8/200116/6/2026
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.
ModificadaMedia (5)8.3%💥 ExploitIkonboard.com Ikonboard27/6/200116/6/2026
Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitrary files via a .. (dot dot) attack in the helpon parameter.
ModificadaMedia (5)5.9%💥 ExploitWay-board2/6/200116/6/2026
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.
ModificadaAlta (10)6.0%💥 ExploitNobreak Technologies CrazywwwboardQdecoder3/5/200116/6/2026
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.
ModificadaBaja (2.1)0.34%—Ultrascripts Ultraboard12/3/200116/6/2026
The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.
ModificadaAlta (10)5.2%—Ikonboard.com Ikonboard12/2/200116/6/2026
register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.
ModificadaMedia (4.6)0.36%—Compaq Easy Access Keyboard Software19/12/200023/9/2026
El software Compaq Easy Access Keyboard 1.3 no deshabilita correctamente el acceso a los botones personalizados cuando la pantalla está bloqueada, lo que podría permitir a un atacante obtener privilegios o ejecutar programas sin autorización.
ModificadaAlta (7.5)1.5%—Blackboard Courseinfo18/7/200016/6/2026
BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privileges by directly calling the supporting CGI programs such as user_update_passwd.pl and user_update_admin.pl.
ModificadaBaja (2.1)0.35%—Blackboard Courseinfo10/7/200016/6/2026
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.
ModificadaMedia (5)2.5%💥 ExploitUltrascripts Ultraboard5/5/200016/6/2026
UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself.
ModificadaMedia (5)3.3%💥 ExploitUltrascripts Ultraboard3/5/200016/6/2026
UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte.
ModificadaAlta (10)3.5%—Infopop Ultimate Bulletin Board11/2/200016/6/2026
Infopop Ultimate Bulletin Board (UBB) allows remote attackers to execute commands via shell metacharacters in the topic hidden field.
ModificadaMedia (5)1.3%—Infopop Ultimate Bulletin Board1/11/199916/6/2026
Ultimate Bulletin Board stores data files in the cgi-bin directory, allowing remote attackers to view the data if an error occurs when the HTTP server attempts to execute the file.
ModificadaAlta (7.5)27%💥 ExploitMicrosoft MSN Setup Bulletin Board Services24/9/199916/6/2026
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.
ModificadaAlta (7.5)1.1%—Matt Wright Wwwboard16/9/199916/6/2026
WWWBoard has a default username and default password.
ModificadaAlta (10)8.6%💥 ExploitMatt Wright Wwwboard16/9/199916/6/2026
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
ModificadaMedia (5)1.5%—Matt Wright Wwwboard3/9/199816/6/2026
wwwboard allows a remote attacker to delete message board articles via a malformed argument.