Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.16% | — | Moore Threads MTT S80 Driver PackageAI | 21/9/2026 | 22/9/2026 | A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about… | |
| Aplazada | Crítica (9.3) | 0.20% | — | Moore Threads MTT S80 Driver PackageAI | 21/9/2026 | 22/9/2026 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about… | |
| Aplazada | Alta (7.1) | 0.40% | — | UBB ThreadsAI | 18/6/2026 | 18/6/2026 | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many registered users, an authenticated attacker can easily exhaust database resources and completely deny access to the application for other users. Because vendor contact attempts… | |
| Aplazada | Alta (8.6) | 0.78% | — | UBB ThreadsAI | 18/6/2026 | 18/6/2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privileges to, what results in Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed… | |
| Aplazada | Alta (8.6) | 0.38% | — | Ubbcentral Ubb.threadsAI | 18/6/2026 | 18/6/2026 | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying database. Due to insufficient input sanitization, an attacker can extract sensitive information, such as user credentials, by manipulating SQL queries through time-based or… | |
| Aplazada | Media (5.1) | 0.45% | — | UBB ThreadsAI | 18/6/2026 | 18/6/2026 | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrary JavaScript in the context of a victim's browser by tricking them into clicking a crafted link. Because vendor contact attempts were unsuccessful, the vulnerability has… | |
| Aplazada | Alta (8.6) | 0.22% | — | UBB ThreadsAI | 18/6/2026 | 18/6/2026 | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also… | |
| Aplazada | Media (5.1) | 0.40% | — | UBB ThreadsAI | 18/6/2026 | 18/6/2026 | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low privileged attackers to inject arbitrary JavaScript that executes in a victim's browser upon viewing. Because vendor contact attempts were unsuccessful, the vulnerability… | |
| Analizada | Media (5.1) | 0.26% | — | Dragonexpert Recent Threads ON Index | 29/4/2026 | 17/6/2026 | MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing… | |
| Analizada | Media (5.1) | 0.20% | — | Mybb Last User Threads | 4/4/2026 | 24/7/2026 | MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users visit the attacker's… | |
| Analizada | Crítica (9.8) | 0.74% | — | Mthreads Torch Musa | 15/12/2025 | 17/6/2026 | MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled file paths without validation, allowing arbitrary code execution. An attacker can… | |
| Modificada | Media (6.5) | 0.59% | — | Thoughtworks Node-worker-threads-pool | 11/8/2023 | 17/6/2026 | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service. | |
| Modificada | Media (6.1) | 0.54% | — | Mybb Active Threads | 24/4/2023 | 17/6/2026 | In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period. | |
| Modificada | Media (5.4) | 0.51% | — | Recent Threads ON Index Project Recent Threads ON Index | 2/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in dragonexpert Recent Threads on Index. Affected is the function recentthread_list_threads of the file inc/plugins/recentthreads/hooks.php of the component Setting Handler. The manipulation of the argument recentthread_forumskip leads to cross site… | |
| Modificada | Media (6.1) | 49% | — | Mybb NEW Threads | 19/7/2018 | 17/6/2026 | The New Threads plugin before 1.2 for MyBB has XSS. | |
| Modificada | Media (5.4) | 1.7% | — | Recent Threads Project Recent Threads | 4/6/2018 | 17/6/2026 | The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject. | |
| Modificada | Media (5.4) | 1.5% | — | Threads TO Link Project Threads TO Link | 1/5/2018 | 17/6/2026 | An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized. | |
| Modificada | Media (4.3) | 1.3% | — | Liquidthreads Project Liquidthreads | 12/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject. | |
| Modificada | Media (4.3) | 2.0% | — | Ubbcentral Ubb.threads | 23/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter. | |
| Modificada | Media (6.9) | 0.44% | — | Pthread-win32 Project Pthreads-win32 | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2.dll in Pthreads-win32 2.8.0 allows local users to gain privileges via a Trojan horse quserex.dll file in the current working directory. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 7.3% | — | Ubbcentral Ubb.threads | 13/8/2009 | 16/6/2026 | SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter. | |
| Modificada | Media (4) | 0.97% | — | Mephisteus THE Personal Sticky Threads | 27/4/2009 | 16/6/2026 | The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky. | |
| Modificada | Alta (7.5) | 0.98% | — | Ubbcentral Ubb.threads | 11/4/2007 | 16/6/2026 | SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter. | |
| Modificada | Media (5) | 1.5% | — | Ubbcentral Ubb.threads | 3/10/2006 | 16/6/2026 | Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 1.6% | — | Ubbcentral Ubb.threads | 3/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[thispath] or (2) GLOBALS[configdir] parameter. |