Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.48% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes.This issue affects Recipe Maker For Your Food Blog from Zip Recipes: from n/a through 8.1.0. | |
| Modificada | Media (6.1) | 0.43% | — | Thirtybees Bees Blog | 30/12/2023 | 17/6/2026 | The beesblog (aka Bees Blog) component before 1.6.2 for thirty bees allows Reflected XSS because controllers/front/post.php sharing_url is mishandled. | |
| Modificada | Crítica (9.8) | 0.91% | — | Forestblog Project Forestblog | 17/12/2023 | 17/6/2026 | A vulnerability classified as critical has been found in saysky ForestBlog up to 20220630. This affects an unknown part of the file /admin/upload/img of the component Image Upload Handler. The manipulation of the argument filename leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 1.0% | — | Cybrosys Website Blog Search | 15/12/2023 | 17/6/2026 | A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component. | |
| Modificada | Alta (8.8) | 0.26% | — | Superblogme Broken Link Checker FOR Youtube | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3. | |
| Modificada | Crítica (9.8) | 4.3% | 💥 Exploit | Infornweb News & Blog Designer Pack | 22/11/2023 | 17/6/2026 | The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked… | |
| Modificada | Media (4.8) | 0.45% | — | Armanidrisi DEV Blog | 21/11/2023 | 17/6/2026 | Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username. | |
| Modificada | Media (5.4) | 0.43% | — | Armanidrisi DEV Blog | 21/11/2023 | 17/6/2026 | Dev blog v1.0 allows to exploit an XSS through an unrestricted file upload, together with a bad entropy of filenames. With this an attacker can upload a malicious HTML file, then guess the filename of the uploaded file and send it to a potential victim. | |
| Modificada | Media (6.1) | 0.47% | — | Wishfulthemes Raise MAGWishfulthemes Wishful Blog | 16/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wishfulthemes Raise Mag, Wishfulthemes Wishful Blog themes allows Reflected XSS.This issue affects Raise Mag: from n/a through 1.0.7; Wishful Blog: from n/a through 2.0.1. | |
| Modificada | Crítica (9.8) | 0.69% | — | Prestahero YBC Blog | 15/11/2023 | 17/6/2026 | ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts(). | |
| Modificada | Alta (8.8) | 0.30% | — | Meril Blog Floating Button | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meril Inc. Blog Floating Button plugin <= 1.4.12 versions. | |
| Modificada | Crítica (9.8) | 0.50% | — | Hdclic Prestablog | 31/10/2023 | 17/6/2026 | In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL injection. The script ajax slider_positions.php has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection. | |
| Modificada | Crítica (9.8) | 0.60% | — | Themevolty Theme Volty CMS Blog | 31/10/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon, tvcmstestimonial components. | |
| Modificada | Media (4.3) | 0.59% | — | Adenion Blog2social | 20/10/2023 | 17/6/2026 | The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only. | |
| Modificada | Alta (7.5) | 0.56% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (8.1) | 0.51% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Crítica (9.8) | 0.70% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (7.5) | 0.56% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Crítica (9.8) | 0.63% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this… | |
| Modificada | Crítica (9.8) | 0.75% | — | Oracle Weblogic Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (8.8) | 0.21% | — | Otwthemes Blog Manager Light | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Blog Manager Light plugin <= 1.20 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Chetangole Wp-copyprotect [protect Your Blog Posts] | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions. | |
| Modificada | Media (5.4) | 0.51% | — | Awplife Blog Filter | 4/10/2023 | 17/6/2026 | The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (5.4) | 0.40% | — | Awplife Blog Filter | 30/9/2023 | 17/6/2026 | The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.5) | 1.4% | — | Tianchoy Blog | 27/9/2023 | 17/6/2026 | SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php |