Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.29% | — | Myupb Ultimate PHP Board | 16/10/2025 | 17/6/2026 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. | |
| Analizada | Media (6.1) | 0.27% | — | Myupb Ultimate PHP Board | 16/10/2025 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. | |
| Modificada | Alta (8.8) | 4.7% | — | Wp-board Project Wp-board | 20/9/2021 | 17/6/2026 | The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. This is a time based SQLI and in the same function vulnerable parameter is passed twice so if we pass time as 5… | |
| Modificada | Media (4.3) | 1.9% | — | Myupb Ultimate PHP Board | 10/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ultimate PHP Board (aka myUPB) before 2.2.8 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to search.php or (2) avatar parameter to profile.php. | |
| Modificada | Media (6.4) | 1.5% | — | Kent-web Clip Board | 28/2/2015 | 17/6/2026 | KENT-WEB Clip Board before 4.1 allows remote attackers to delete arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Kent-web Clip Board | 5/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Pbboard | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by… | |
| Modificada | Media (6.8) | 2.6% | — | Pbboard | 27/8/2012 | 16/6/2026 | Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers… | |
| Modificada | Alta (7.5) | 3.1% | — | Pbboard | 12/8/2012 | 16/6/2026 | The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password parameters to index.php. | |
| Modificada | Alta (7.5) | 2.5% | — | Pbboard | 12/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in PBBoard 2.1.4 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to the send page, (2) email parameter to the forget page, (3) password parameter to the forum_archive page, (4) section parameter to the management page, (5) section_id… | |
| Modificada | Media (6.8) | 0.63% | — | Pbboard | 21/2/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in PBBoard 2.1.4 allow remote attackers to hijack the authentication of administrators for requests that (1) upload a file via an add action or (2) change the contents of a file via a dit action. | |
| Modificada | Media (4.3) | 1.5% | — | Rocomotion P BoardRocomotion P Diary RRocomotion P ForumRocomotion P Link+6 | 20/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM… | |
| Modificada | Media (4.6) | 0.45% | — | Intel Desktop Board | 8/2/2010 | 16/6/2026 | Unspecified vulnerability in the BIOS in Intel Desktop Board DB, DG, DH, DP, and DQ Series allows local administrators to execute arbitrary code in System Management Mode (SSM) via unknown attack vectors. | |
| Modificada | Media (4.3) | 0.84% | — | Pbboard | 9/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forums/index.php in Power Bulletin Board (PBBoard) 2.0.2 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a new_topic action. | |
| Modificada | Alta (7.5) | 2.4% | — | Myupb Flat PHP Board | 17/12/2007 | 16/6/2026 | Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inject arbitrary PHP code via the (1) username, (2) password, and (3) email parameters when registering a user account, which can be executed by accessing the user's php file for this account. NOTE:… | |
| Modificada | Media (6.5) | 2.1% | — | Myupb Flat PHP Board | 17/12/2007 | 16/6/2026 | index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current user account by reading the password parameter value in the HTML source for the page generated by a profile action. | |
| Modificada | Alta (7.5) | 3.4% | — | GPL PHP Board | 24/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in GPL PHP Board (GPB) unstable-2001.11.14-1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) db.mysql.inc.php or (2) gpb.inc.php in include/, or the (3) theme parameter to themes/ubb/login.php. | |
| Modificada | Media (6.8) | 5.1% | — | Ultimate PHP Board | 20/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Ultimate PHP Board | 28/12/2006 | 16/6/2026 | Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php. | |
| Modificada | Media (5) | 1.8% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which… | |
| Modificada | Media (5) | 1.0% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to create arbitrary accounts via the "[NR]" sequence in the signature field, which is used to separate multiple records. | |
| Modificada | Media (5) | 1.4% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions. | |
| Modificada | Media (5) | 1.3% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injecting a Perl CGI script using "[NR]" sequences in the message… | |
| Modificada | Media (6.5) | 1.4% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which… | |
| Modificada | Alta (10) | 2.7% | — | Ultimate PHP Board | 24/6/2006 | 16/6/2026 | The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges. |