Vulnerabilities
Summary — last 7 days
New vulnerabilities2,700▼ 69 vs. last week
Critical / high1,449▲ 307 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Low (2.1) | 0.34% | — | Ultrascripts Ultraboard | 3/12/2001 | 6/16/2026 | The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs. | |
| Modified | Medium (5) | 2.5% | — | Ultrascripts Ultraboard | 5/5/2000 | 6/16/2026 | UltraBoard 1.6 and other versions allow remote attackers to cause a denial of service by referencing UltraBoard in the Session parameter, which causes UltraBoard to fork copies of itself. | |
| Modified | Medium (5) | 3.3% | — | Ultrascripts Ultraboard | 5/3/2000 | 6/16/2026 | UltraBoard.pl or UltraBoard.cgi CGI scripts in UltraBoard 1.6 allows remote attackers to read arbitrary files via a pathname string that includes a dot dot (..) and ends with a null byte. |