Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | LayerbbAI | 16/5/2026 | 17/6/2026 | LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extract sensitive… | |
| Modificada | Alta (8.8) | 2.5% | — | Layerbb | 20/9/2019 | 17/6/2026 | LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. | |
| Modificada | Alta (8.8) | 0.61% | — | Layerbb | 19/7/2019 | 17/6/2026 | LayerBB 1.1.3 allows conversations.php/cmd/new CSRF. | |
| Modificada | Crítica (9.8) | 1.8% | — | Layerbb | 19/7/2019 | 17/6/2026 | LayerBB 1.1.3 allows admin/general.php arbitrary file upload because the custom_logo filename suffix is not restricted, and .php may be used. | |
| Modificada | Media (6.1) | 0.86% | — | Layerbb | 19/7/2019 | 17/6/2026 | LayerBB 1.1.3 allows XSS via the application/commands/new.php pm_title variable, a related issue to CVE-2019-17997. | |
| Modificada | Media (6.1) | 3.6% | — | Layerbb | 21/3/2019 | 17/6/2026 | LayerBB 1.1.1 allows XSS via the titles of conversations (PMs). | |
| Modificada | Media (6.5) | 3.0% | — | Layerbb | 21/3/2019 | 17/6/2026 | LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/. | |
| Modificada | Crítica (9.8) | 2.0% | — | Layerbb | 7/3/2019 | 17/6/2026 | LayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter. |