Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1659 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 16/5/2005 | 16/6/2026 | SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image. | |
| Modificada | Alta (7.5) | 1.1% | — | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing. | |
| Modificada | Media (6.8) | 1.3% | — | Invisionpower Invision Power BoardAI | 3/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Invision Power Services Invision Board | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Board | 11/4/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision Power Board | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una etiqueta IMG en una etiqueta COLOR cuyo estilo está puesto como background:url. | |
| Modificada | Media (5) | 1.9% | — | Geovision Geohttpserver | 31/12/2004 | 16/6/2026 | The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Invision Power Services Invision Power TOP Site List | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Invision Power Services Invision Board | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Invision Power Services Invision Power Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header. | |
| Modificada | Media (4.3) | 0.95% | — | Invision Power Services Invision Power Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php. | |
| Modificada | Alta (7.5) | 3.8% | — | PAN Vision I.g.i-2 Covert Strike | 31/12/2004 | 16/6/2026 | Format string vulnerability in the logging function in IGI 2 Covert Strike server 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in RCON commands. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Invision Power Services Invision Gallery | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters. | |
| Modificada | Media (5) | 1.4% | — | Geovision Geohttpserver | 31/12/2004 | 16/6/2026 | GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines). | |
| Modificada | Alta (10) | 2.4% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter. | |
| Modificada | Media (6.8) | 5.6% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters. | |
| Modificada | Media (5) | 1.7% | — | Invision Power Services Invision Board | 23/11/2004 | 16/6/2026 | Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image file, which displays the installation path in an error message. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Activision Call OF DutyActivision Call OF Duty United Offensive | 5/9/2004 | 16/6/2026 | Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430. | |
| Modificada | Alta (7.5) | 1.4% | — | Invision Power Services Invision Board | 3/1/2004 | 16/6/2026 | SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable. | |
| Modificada | Media (5) | 1.2% | — | Invision Power Services Invision Board | 31/12/2003 | 16/6/2026 | Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access. | |
| Modificada | Media (6.8) | 4.0% | 💥 Exploit | Invision Power Services Invision Power Board | 31/12/2003 | 16/6/2026 | ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code. |