Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.16%—Moore Threads MTT S80 Driver PackageAI21/9/202622/9/2026
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about…
AplazadaCrítica (9.3)0.20%—Moore Threads MTT S80 Driver PackageAI21/9/202622/9/2026
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about…
AplazadaAlta (7.1)0.40%—UBB ThreadsAI18/6/202618/6/2026
UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile on instances with many registered users, an authenticated attacker can easily exhaust database resources and completely deny access to the application for other users. Because vendor contact attempts…
AplazadaAlta (8.6)0.78%—UBB ThreadsAI18/6/202618/6/2026
UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any file on the application’s server that application has privileges to, what results in Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed…
AplazadaAlta (8.6)0.38%—Ubbcentral Ubb.threadsAI18/6/202618/6/2026
UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to interact with the underlying database. Due to insufficient input sanitization, an attacker can extract sensitive information, such as user credentials, by manipulating SQL queries through time-based or…
AplazadaMedia (5.1)0.45%—UBB ThreadsAI18/6/202618/6/2026
UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrary JavaScript in the context of a victim's browser by tricking them into clicking a crafted link. Because vendor contact attempts were unsuccessful, the vulnerability has…
AplazadaAlta (8.6)0.22%—UBB ThreadsAI18/6/202618/6/2026
uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenticated user into executing unintended actions. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also…
AplazadaMedia (5.1)0.40%—UBB ThreadsAI18/6/202618/6/2026
UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly sanitize user input, allowing low privileged attackers to inject arbitrary JavaScript that executes in a victim's browser upon viewing. Because vendor contact attempts were unsuccessful, the vulnerability…
AnalizadaMedia (5.1)0.26%—Dragonexpert Recent Threads ON Index29/4/202617/6/2026
MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers of all users viewing…
AnalizadaMedia (5.1)0.20%—Mybb Last User Threads4/4/202624/7/2026
MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users visit the attacker's…
AnalizadaCrítica (9.8)0.74%—Mthreads Torch Musa15/12/202517/6/2026
MooreThreads torch_musa through all versions contains an unsafe deserialization vulnerability in torch_musa.utils.compare_tool. The compare_for_single_op() and nan_inf_track_for_single_op() functions use pickle.load() on user-controlled file paths without validation, allowing arbitrary code execution. An attacker can…
ModificadaMedia (6.5)0.59%—Thoughtworks Node-worker-threads-pool11/8/202317/6/2026
An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a denial of service.
ModificadaMedia (6.1)0.54%—Mybb Active Threads24/4/202317/6/2026
In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a time period.
ModificadaMedia (5.4)0.51%—Recent Threads ON Index Project Recent Threads ON Index2/1/202317/6/2026
A vulnerability, which was classified as problematic, was found in dragonexpert Recent Threads on Index. Affected is the function recentthread_list_threads of the file inc/plugins/recentthreads/hooks.php of the component Setting Handler. The manipulation of the argument recentthread_forumskip leads to cross site…
ModificadaMedia (6.1)49%—Mybb NEW Threads19/7/201817/6/2026
The New Threads plugin before 1.2 for MyBB has XSS.
ModificadaMedia (5.4)1.7%—Recent Threads Project Recent Threads4/6/201817/6/2026
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
ModificadaMedia (5.4)1.5%—Threads TO Link Project Threads TO Link1/5/201817/6/2026
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.
ModificadaMedia (4.3)1.3%—Liquidthreads Project Liquidthreads12/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject.
ModificadaMedia (4.3)2.0%—Ubbcentral Ubb.threads23/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in forums/ubbthreads.php in UBB.threads 7.5.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the Loginname parameter.
ModificadaMedia (6.9)0.44%—Pthread-win32 Project Pthreads-win327/9/201216/6/2026
Untrusted search path vulnerability in the pthread_win32_process_attach_np function in pthreadGC2.dll in Pthreads-win32 2.8.0 allows local users to gain privileges via a Trojan horse quserex.dll file in the current working directory. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)7.3%—Ubbcentral Ubb.threads13/8/200916/6/2026
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.
ModificadaMedia (4)0.97%—Mephisteus THE Personal Sticky Threads27/4/200916/6/2026
The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.
ModificadaAlta (7.5)0.98%—Ubbcentral Ubb.threads11/4/200716/6/2026
SQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the C parameter.
ModificadaMedia (5)1.5%—Ubbcentral Ubb.threads3/10/200616/6/2026
Groupee UBB.threads 6.5.1.1 allows remote attackers to obtain sensitive information via a direct request for cron/php/subscriptions.php, which reveals the path in an error message.
ModificadaAlta (7.5)1.6%—Ubbcentral Ubb.threads3/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[thispath] or (2) GLOBALS[configdir] parameter.