Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.81%—Leotheme Leoblog15/9/202317/6/2026
LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.
ModificadaMedia (6.1)0.41%—Adenion Blog2social6/9/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.
ModificadaMedia (4.3)0.55%—Riverforest-wp Simple Blog Card30/8/202317/6/2026
The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones
ModificadaMedia (5.4)0.43%—Riverforest-wp Simple Blog Card30/8/202317/6/2026
The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)4.1%💥 ExploitThemevolty Theme Volty CMS Blog28/8/202317/6/2026
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
ModificadaAlta (7.2)1.2%—Perfreeblog28/8/202317/6/2026
An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list.
ModificadaCrítica (9.8)1.4%—Weblogic-framework Project Weblogic-framework25/8/202317/6/2026
weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly deserializes the data returned by the…
ModificadaMedia (6.1)0.90%💥 ExploitAdenion Blog2social21/8/202317/6/2026
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaAlta (7.8)0.36%—Berkaygediz O Blog21/8/20239/7/2026
SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.
ModificadaMedia (6.1)0.38%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions.
ModificadaMedia (6.1)0.38%—Everestthemes Mocho Blog8/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions.
ModificadaMedia (6.5)0.65%—Oracle Weblogic Server18/7/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server.…
ModificadaMedia (4.4)0.55%—Oracle Weblogic Server18/7/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful…
ModificadaAlta (8.8)0.26%—Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions.
ModificadaMedia (4.3)0.50%—Butlerblog Wp-members12/7/202317/6/2026
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on…
ModificadaMedia (6.1)0.39%—Simplephpscripts Simple Blog30/6/202317/6/2026
A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is…
ModificadaCrítica (9.8)26%💥 PoCBlogengine.net26/6/202317/6/2026
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
ModificadaMedia (6.1)31%💥 ExploitBlogengine.net21/6/202317/6/2026
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
ModificadaAlta (8.8)0.43%—Wordpress Blogger Importer4/6/202316/6/2026
A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is…
ModificadaMedia (4.8)0.48%—Blog-in-blog Project Blog-in-blog31/5/202317/6/2026
The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor-level and…
ModificadaAlta (7.2)1.1%—Blog-in-blog Project Blog-in-blog31/5/202317/6/2026
The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to…
ModificadaMedia (5.4)0.41%—Djangoblog Project Djangoblog29/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
ModificadaCrítica (9.8)0.94%—Perfreeblog18/5/202317/6/2026
An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.
ModificadaMedia (6.1)0.38%—Everestthemes Viable Blog10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Viable Blog theme <= 1.1.4 versions.
ModificadaAlta (7.8)0.97%—Mblog Project Mblog8/5/202317/6/2026
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.