Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to obtain sensitive database information via vectors involving templates. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving pruning logs. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mod control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving editing users. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors involving Mod control panel logs. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the User control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 1.3% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via vectors related to login. | |
| Modificada | Crítica (9.8) | 2.6% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check. | |
| Modificada | Crítica (9.8) | 2.1% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation path via vectors involving error log files. | |
| Modificada | Media (6.1) | 1.0% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via vectors related to "old upgrade files." | |
| Modificada | Media (6.1) | 1.7% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the error handler in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (10) | 2.1% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.3) | 1.6% | — | Mybb Merge SystemMybb | 31/1/2017 | 17/6/2026 | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password. | |
| Modificada | Media (6.5) | 2.7% | — | Cisco Emergency Responder | 14/12/2016 | 17/6/2026 | A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb57494.… | |
| Modificada | Alta (8.8) | 1.2% | — | Cisco Emergency Responder | 14/12/2016 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvb06663. Known Affected Releases: 11.5(1.10000.4). Known… | |
| Modificada | Media (4) | 1.6% | — | Cisco Emergency Responder | 13/12/2015 | 17/6/2026 | Cisco Emergency Responder 10.5(3.10000.9) allows remote attackers to upload files to arbitrary locations via a crafted parameter, aka Bug ID CSCuv25501. | |
| Modificada | Media (4) | 2.3% | — | Cisco Emergency Responder | 13/12/2015 | 17/6/2026 | Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781. | |
| Modificada | Media (6.8) | 0.98% | — | Cisco Emergency Responder | 13/12/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501. | |
| Modificada | Media (4.3) | 0.95% | — | Cisco Emergency Responder | 13/12/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547. | |
| Modificada | Baja (3.5) | 0.95% | — | Term Merge Project Term Merge | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Emergency Responder | 4/4/2014 | 17/6/2026 | Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Emergency Responder | 4/4/2014 | 17/6/2026 | Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882. | |
| Modificada | Media (6.8) | 0.64% | — | Cisco Emergency Responder | 4/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250. | |
| Modificada | Media (4.3) | 1.8% | — | Cisco Emergency Responder | 4/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384. |