Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Jelsoft Vbulletin | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg. | |
| Modificada | Alta (10) | 2.2% | — | Mybulletinboard | 13/12/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0 have unknown impact and attack vectors, a different set of vulnerabilities than those identified by CVE-2005-4199. | |
| Modificada | Media (4.3) | 0.94% | — | Mybulletinboard | 23/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.0 PR2 Rev 686 allow remote attackers to inject arbitrary web script or HTML via (1) the subject field when creating a new thread and (2) information passed to the Reputation system. | |
| Modificada | Media (5) | 1.3% | — | Mybulletinboard | 23/11/2005 | 16/6/2026 | MyBulletinBoard (MyBB) 1.0 PR2 Rev 686 allows remote attackers to delete or move private messages (PM) via modified fields in the inbox form. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Mybulletinboard | 27/10/2005 | 16/6/2026 | SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter in dereferrer.php and (2) the file parameter in imagewin.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) login field, (2) "search this thread" feature, (3) "search for posts" feature, (4) "forgot password" feature, (5) list parameter in… | |
| Modificada | Media (5) | 1.6% | — | Versatilebulletinboard | 20/10/2005 | 16/6/2026 | getversions.php in versatileBulletinBoard (vBB) 1.0.0 RC2 lists the versions of all installed scripts, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Baja (2.1) | 0.92% | — | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid… | |
| Modificada | Media (4.3) | 1.0% | — | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php. | |
| Modificada | Media (4.3) | 0.99% | — | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9)… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to… | |
| Modificada | Alta (7.5) | 1.2% | — | Jelsoft Vbulletin | 21/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6)… | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard MybbAI | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) Preview Release 2 allow remote attackers to execute arbitrary SQL commands via the (1) fid parameter to misc.php or (2) Content-Disposition field in the HTTP header to newreply.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Mybulletinboard | 2/9/2005 | 16/6/2026 | SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL statements via the fid parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Mybulletinboard | 26/8/2005 | 16/6/2026 | SQL injection vulnerability in search.php for MyBulletinBoard (MyBB) 1.00 Release Candidate 1 through 4 allows remote attackers to execute arbitrary SQL commands via the uid parameter. NOTE: this issue might overlap CVE-2005-0282. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mybulletinboard | 16/8/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 with Security Patch allow remote attackers to execute arbitrary SQL commands via the Username field in (1) index.php or (2) member.php, action parameter to (3) search.php or (4) member.php, or (5) polloptions parameter to polls.php. | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 1/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Mybulletinboard | 31/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4) pid parameter to editpost.php, (5) fid parameter to… | |
| Modificada | Media (4.3) | 1.3% | — | Mybulletinboard | 31/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut parameter to forumdisplay.php, (6) username, (7) email, or (8)… | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Azbb AZ Bulletin Board | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in main_index.php in AZ Bulletin Board (AZbb) 1.0.07a through 1.0.07c allows remote attackers to execute arbitrary PHP code by modifying the (1) dir_src or (2) abs_layer parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 1.9% | 💥 Exploit | Jelsoft Vbulletin | 2/5/2005 | 16/6/2026 | Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Mybulletinboard | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in member.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the uid parameter. |