Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.48% | — | Wander-chu Springboot-blog | 9/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the function preHandle of the file src/main/java/com/my/blog/website/interceptor/BaseInterceptor.java of the component HTTP POST Request Handler. The manipulation leads to improper access controls. It is… | |
| Analizada | Media (5.3) | 0.46% | — | Mtons Mblog | 9/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.3) | 0.68% | — | Mtons Mblog | 9/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is… | |
| Analizada | Media (5.3) | 0.41% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Zerowdd MyblogAI | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.55% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 0.60% | — | Zblogcn Z-blogphp | 6/1/2025 | 17/6/2026 | Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template. | |
| Analizada | Media (5.3) | 0.43% | — | Zhenfeng13 My-blog | 6/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The manipulation of the argument file leads to unrestricted upload. The attack can be launched… | |
| Analizada | Media (5.3) | 0.43% | — | Zhenfeng13 My-blog | 6/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the argument editormd-image-file leads to unrestricted upload. It is possible to launch… | |
| Aplazada | Media (4.3) | 0.18% | — | Volthemes Patricia BlogAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Blog allows Cross Site Request Forgery.This issue affects Patricia Blog: from n/a through 1.2. | |
| Aplazada | Alta (7.1) | 0.41% | — | Preblogging Increase SociabilityAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in preblogging Increase Sociability increase-sociability allows Reflected XSS.This issue affects Increase Sociability: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.5) | 0.39% | — | Best WP Developer Advanced Blog Post BlockAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer Advanced Blog Post Block advanced-blog-post-block allows Stored XSS.This issue affects Advanced Blog Post Block: from n/a through <= 1.0.4. | |
| Aplazada | Media (4.3) | 0.43% | — | Netweblogic Login With AjaxAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Marcus (aka @msykes) Login With Ajax login-with-ajax allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login With Ajax: from n/a through <= 4.1. | |
| Aplazada | Media (4.3) | 0.40% | — | Sparkle Themes Blogger BuzzAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sparkle Themes Blogger Buzz allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Blogger Buzz: from n/a through 1.2.2. | |
| Aplazada | Media (4.3) | 0.25% | — | EleblogAI | 4/12/2024 | 17/6/2026 | The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the goodbye_form_callback() function in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (7.1) | 0.17% | — | Rockemmusic Favicon MY BlogAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rockemmusic Favicon My Blog favicon-my-blog allows Stored XSS.This issue affects Favicon My Blog: from n/a through <= 1.0.2. | |
| Aplazada | Alta (7.5) | 0.64% | — | Softpulseinfotech SP Blog DesignerAI | 28/11/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.4) | 0.73% | — | Easy LiveblogsAI | 23/11/2024 | 17/6/2026 | The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.20% | — | Naver BlogAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hints Naver Blog naver-blog-api allows Stored XSS.This issue affects Naver Blog: from n/a through <= 1.0. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Dmcwebzone Airin BlogAI | 16/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a through <= 1.6.1. | |
| Aplazada | Alta (7.5) | 0.47% | — | Blogger 301 RedirectAI | 16/11/2024 | 17/6/2026 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Crítica (9.8) | 1.5% | 💥 PoC | Websiteinwp Blogpoet | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WebsiteinWP Blogpoet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blogpoet: from n/a through 1.0.3. | |
| Aplazada | Crítica (9.8) | 36% | 💥 PoC | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which… | |
| Aplazada | Crítica (9.8) | 0.56% | — | WUX Blog EditorAI | 26/10/2024 | 17/6/2026 | The Wux Blog Editor plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.0. This is due to missing validation on the token being supplied during the autologin through the plugin. This makes it possible for unauthenticated attackers to log in to the first administrator user. |