Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.21% | — | Softpulseinfotech SP Blog DesignerAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SP Blog Designer: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.5) | 0.48% | — | Appleple A-blog CMS | 31/3/2025 | 17/6/2026 | Untrusted data deserialization vulnerability exists in a-blog cms. Processing a specially crafted request may store arbitrary files on the server where the product is running. This can be leveraged to execute an arbitrary script on the server. | |
| Aplazada | Alta (7.1) | 0.13% | — | Efficientscripts Microblog PosterAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Efficient Scripts Microblog Poster microblog-poster allows Stored XSS.This issue affects Microblog Poster: from n/a through <= 2.1.6. | |
| Aplazada | Media (6.5) | 0.25% | — | Plugin-devs Blog Posts AND Category Filter FOR ElementorAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plugin Devs Blog, Posts and Category Filter for Elementor blog-posts-and-category-for-elementor allows Stored XSS.This issue affects Blog, Posts and Category Filter for Elementor: from n/a through <= 2.0.1. | |
| Analizada | Media (5.3) | 0.34% | — | Zhyd Oneblog | 27/3/2025 | 17/6/2026 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.71% | — | Zhyd Oneblog | 27/3/2025 | 17/6/2026 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Analizada | Media (5.1) | 0.30% | — | Lenve Vblog | 17/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the argument mdContent/htmlContent leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.65% | — | Lenve Vblog | 17/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The… | |
| Analizada | Media (4.8) | 0.39% | — | Otale Tale Blog | 16/3/2025 | 17/6/2026 | A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save of the component Site Settings. The manipulation of the argument Site Title leads to cross site scripting. The attack can be initiated remotely. The… | |
| Analizada | Media (6.9) | 0.92% | — | Otale Tale Blog | 16/3/2025 | 17/6/2026 | A vulnerability was found in otale Tale Blog 2.0.5. It has been classified as problematic. This affects an unknown part of the file /%61dmin/api/logs. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.8) | 0.25% | — | Gkdv Blogbuzztime FOR WP | 12/3/2025 | 17/6/2026 | The BlogBuzzTime for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Alta (7.1) | 0.39% | — | Thebloghouse ComparepressAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thebloghouse ComparePress comparepress allows Reflected XSS.This issue affects ComparePress: from n/a through <= 2.0.8. | |
| Aplazada | Media (6.5) | 0.27% | — | Dnngo XblogAI | 11/2/2025 | 17/6/2026 | DNNGo xBlog v6.5.0 was discovered to contain a SQL injection vulnerability via the Categorys parameter at /DNNGo_xBlog/Resource_Service.aspx. | |
| Analizada | Alta (8) | 0.45% | — | Zhyd Oneblog | 10/2/2025 | 17/6/2026 | OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department. | |
| Analizada | Media (4.8) | 0.28% | — | Forestblog Project Forestblog | 3/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the article editing function. | |
| Analizada | Media (6.1) | 0.26% | — | Suhas93 SEO Blogger TO Wordpress 301 Redirector | 23/1/2025 | 17/6/2026 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.30% | — | Thaikolja Flexible-blogtitleAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thaikolja Flexible Blogtitle flexible-blogtitle allows Reflected XSS.This issue affects Flexible Blogtitle: from n/a through <= 0.1. | |
| Analizada | Alta (7.5) | 0.55% | — | Oracle Weblogic Server | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 0.82% | — | Oracle Weblogic Server | 21/1/2025 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Aplazada | Alta (7.1) | 0.23% | — | Xkollsoftware Social2blogAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xkollsoftware Social2Blog social2blog allows Reflected XSS.This issue affects Social2Blog: from n/a through <= 0.2.990. | |
| Aplazada | Media (6.5) | 0.37% | — | Scottwallick Blog SummaryAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottwallick Blog Summary blog-summary allows Stored XSS.This issue affects Blog Summary: from n/a through <= 0.1.2 β. | |
| Aplazada | Alta (7.1) | 0.31% | — | Poco Blogger Image ImportAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poco Blogger Image Import allows Stored XSS.This issue affects Blogger Image Import: from 2.1 through n/a. | |
| Aplazada | Media (6.9) | 0.45% | — | Blog Botz FOR Journal ThemeAIOpencartAI | 14/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.1) | 0.40% | — | Wander-chu Springboot-blog | 9/1/2025 | 17/6/2026 | A vulnerability was found in wander-chu SpringBoot-Blog 1.0 and classified as problematic. This issue affects the function modifiyArticle of the file src/main/java/com/my/blog/website/controller/admin/PageController.java of the component Blog Article Handler. The manipulation of the argument content leads to cross… | |
| Analizada | Media (5.1) | 0.51% | — | Wander-chu Springboot-blog | 9/1/2025 | 17/6/2026 | A vulnerability has been found in wander-chu SpringBoot-Blog 1.0 and classified as critical. This vulnerability affects the function upload of the file src/main/java/com/my/blog/website/controller/admin/AttachtController.java of the component Admin Attachment Handler. The manipulation of the argument file leads to… |