Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.81% | — | Leotheme Leoblog | 15/9/2023 | 17/6/2026 | LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs. | |
| Modificada | Media (6.1) | 0.41% | — | Adenion Blog2social | 6/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions. | |
| Modificada | Media (4.3) | 0.55% | — | Riverforest-wp Simple Blog Card | 30/8/2023 | 17/6/2026 | The Simple Blog Card WordPress plugin before 1.32 does not ensure that posts to be displayed via a shortcode are public, allowing any authenticated users, such as subscriber, to retrieve arbitrary post title and their content such as draft, private and password protected ones | |
| Modificada | Media (5.4) | 0.43% | — | Riverforest-wp Simple Blog Card | 30/8/2023 | 17/6/2026 | The Simple Blog Card WordPress plugin before 1.31 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 4.1% | 💥 Exploit | Themevolty Theme Volty CMS Blog | 28/8/2023 | 17/6/2026 | Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single. | |
| Modificada | Alta (7.2) | 1.2% | — | Perfreeblog | 28/8/2023 | 17/6/2026 | An issue in Perfree PerfreeBlog v.3.1.2 allows a remote attacker to execute arbitrary code via crafted plugin listed in admin/plugin/access/list. | |
| Modificada | Crítica (9.8) | 1.4% | — | Weblogic-framework Project Weblogic-framework | 25/8/2023 | 17/6/2026 | weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly deserializes the data returned by the… | |
| Modificada | Media (6.1) | 0.90% | 💥 Exploit | Adenion Blog2social | 21/8/2023 | 17/6/2026 | The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.8) | 0.36% | — | Berkaygediz O Blog | 21/8/2023 | 9/7/2026 | SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component. | |
| Modificada | Media (6.1) | 0.38% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.6 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Everestthemes Mocho Blog | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions. | |
| Modificada | Media (6.5) | 0.65% | — | Oracle Weblogic Server | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle WebLogic Server.… | |
| Modificada | Media (4.4) | 0.55% | — | Oracle Weblogic Server | 18/7/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.1.0.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (8.8) | 0.26% | — | Really-simple-plugins Recipe Maker FOR Your Food Blog From ZIP Recipes | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.0.7 versions. | |
| Modificada | Media (4.3) | 0.50% | — | Butlerblog Wp-members | 12/7/2023 | 17/6/2026 | The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on… | |
| Modificada | Media (6.1) | 0.39% | — | Simplephpscripts Simple Blog | 30/6/2023 | 17/6/2026 | A vulnerability has been found in SimplePHPscripts Simple Blog 3.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. It is… | |
| Modificada | Crítica (9.8) | 26% | 💥 PoC | Blogengine.net | 26/6/2023 | 17/6/2026 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | |
| Modificada | Media (6.1) | 31% | 💥 Exploit | Blogengine.net | 21/6/2023 | 17/6/2026 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | |
| Modificada | Alta (8.8) | 0.43% | — | Wordpress Blogger Importer | 4/6/2023 | 16/6/2026 | A vulnerability was found in Blogger Importer Plugin up to 0.5 on WordPress. It has been classified as problematic. Affected is the function start/restart of the file blogger-importer.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. Upgrading to version 0.6 is… | |
| Modificada | Media (4.8) | 0.48% | — | Blog-in-blog Project Blog-in-blog | 31/5/2023 | 17/6/2026 | The Blog-in-Blog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blog_in_blog' shortcode in versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor-level and… | |
| Modificada | Alta (7.2) | 1.1% | — | Blog-in-blog Project Blog-in-blog | 31/5/2023 | 17/6/2026 | The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Media (5.4) | 0.41% | — | Djangoblog Project Djangoblog | 29/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | |
| Modificada | Crítica (9.8) | 0.94% | — | Perfreeblog | 18/5/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Media (6.1) | 0.38% | — | Everestthemes Viable Blog | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Viable Blog theme <= 1.1.4 versions. | |
| Modificada | Alta (7.8) | 0.97% | — | Mblog Project Mblog | 8/5/2023 | 17/6/2026 | OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. |