Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.28% | — | SIR Gnuboard | 23/10/2025 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php. | |
| Analizada | Media (6.5) | 0.23% | — | SIR Gnuboard | 23/10/2025 | 17/6/2026 | gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php. | |
| Analizada | Baja (2) | 0.25% | — | SIR Gnuboard | 18/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php. | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component. | |
| Analizada | Media (6.1) | 0.52% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php. | |
| Modificada | Media (6.1) | 0.39% | — | SIR Gnuboard | 26/8/2024 | 17/6/2026 | There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. | |
| Analizada | Alta (8.8) | 0.29% | — | SIR Gnuboard | 12/8/2024 | 17/6/2026 | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. | |
| Analizada | Media (6.1) | 0.41% | — | SIR Gnuboard | 14/5/2024 | 17/6/2026 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. | |
| Analizada | Media (6.1) | 0.53% | — | SIR Gnuboard | 16/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. | |
| Modificada | Alta (7.5) | 0.67% | — | SIR Gnuboard | 20/2/2023 | 17/6/2026 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password. | |
| Modificada | Media (5.4) | 0.42% | — | SIR Gnuboard | 12/11/2022 | 17/6/2026 | A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 5.5.8.2.1… | |
| Modificada | Media (6.1) | 0.70% | — | SIR Gnuboard | 16/5/2022 | 17/6/2026 | Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php. | |
| Modificada | Crítica (9.1) | 0.55% | — | SIR Gnuboard | 11/4/2022 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when… | |
| Modificada | Media (6.1) | 1.8% | — | Gnuboard5 | 14/12/2021 | 17/6/2026 | gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the act parameter in bbs/move_update.php. | |
| Modificada | Crítica (9.8) | 5.4% | — | SIR Gnuboard | 24/6/2021 | 17/6/2026 | SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php. | |
| Modificada | Media (6.1) | 1.2% | — | SIR Gnuboard | 7/11/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter. | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 30/10/2019 | 17/6/2026 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter. | |
| Modificada | Media (6.1) | 1.4% | — | SIR Gnuboard | 26/8/2019 | 17/6/2026 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "homepage title" parameter, aka the adm/config_form_update.php cf_title parameter. | |
| Modificada | Media (6.1) | 1.6% | — | SIR Gnuboard | 23/7/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board tail contents" parameter, aka the adm/board_form_update.php bo_mobile_content_tail parameter. | |
| Modificada | Media (6.1) | 1.5% | — | SIR Gnuboard | 23/7/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "mobile board title contents" parameter, aka the adm/board_form_update.php bo_mobile_subject parameter. | |
| Modificada | Media (6.1) | 1.5% | — | SIR Gnuboard | 23/7/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board head contents" parameter, aka the adm/board_form_update.php bo_content_head parameter. | |
| Modificada | Media (6.1) | 1.5% | — | SIR Gnuboard | 23/7/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Extra Contents" parameter, aka the adm/config_form_update.php cf_1~10 parameter. |