Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.9) | 0.82% | — | Akiva Webboard | 4/10/2012 | 16/6/2026 | Akiva WebBoard 8.x stores passwords in plaintext, which allows local users to obtain sensitive information by reading from the database. | |
| Modificada | Alta (7.5) | 1.2% | — | Akiva Webboard | 4/10/2012 | 16/6/2026 | SQL injection vulnerability in WB/Default.asp in Akiva WebBoard before 8 SR 1 allows remote attackers to execute arbitrary SQL commands via the name parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 3.1% | — | Akiva Webboard | 27/7/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in view.php in Webboard 2.90 beta and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Aspthai.net Webboard | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 3.1% | — | Phpstreet Webboard | 23/1/2009 | 16/6/2026 | Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc. | |
| Modificada | Alta (7.5) | 0.97% | — | Phpstreet Webboard | 23/1/2009 | 16/6/2026 | SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 0.91% | — | Deeserver Ultimate Webboard | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL commands via the Category parameter. | |
| Modificada | Alta (7.5) | 1.00% | — | How2asp Webboard | 22/5/2008 | 16/6/2026 | SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary SQL commands via the qNo parameter. | |
| Modificada | Baja (3.5) | 0.83% | — | Akiva Webboard | 25/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the form field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 0.97% | — | Porar Webboard | 27/2/2008 | 16/6/2026 | SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands via the QID parameter. | |
| Modificada | Media (5) | 5.2% | — | Oreilly Webboard | 18/10/2001 | 16/6/2026 | Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands. | |
| Modificada | Media (5) | 7.3% | — | Sixhead Six-webboard | 13/8/2001 | 16/6/2026 | generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter. |