Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Personal Blog CMS Project Personal Blog CMS | 22/12/2021 | 17/6/2026 | Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Fantastic Blog CMS Project Fantastic Blog CMS | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php. | |
| Modificada | Media (6.1) | 0.66% | — | Appleple A-blog CMS | 26/12/2019 | 17/6/2026 | a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitrary scripts to be executed in the context of the application due to unspecified vectors. | |
| Modificada | Media (6.1) | 0.78% | — | Appleple A-blog CMS | 26/12/2019 | 17/6/2026 | Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Geniusocean Mymagazine Magazine & Blog CMS | 31/10/2017 | 17/6/2026 | MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | |
| Modificada | Media (6.1) | 1.2% | — | Appleple A-blog CMS | 12/4/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (6.5) | 1.3% | — | Appleple A-blog CMS | 12/4/2017 | 17/6/2026 | The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Blog CMS | 25/1/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BLOG:CMS 4.2.1.c allow remote attackers to execute arbitrary PHP code via a URL in the (1) DIR_PLUGINS parameter to (a) index.php, and the (2) DIR_LIBS parameter to (b) media.php and (c) xmlrpc/server.php in admin/. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Blog CMS | 18/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Blog CMS | 18/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Dblog CMS | 21/9/2007 | 16/6/2026 | dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for dblog.mdb. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | PHP Blog CMS | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DIR_ADMIN parameter. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | F-art Agency Blog CMS | 22/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the FADDR parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | F-art Agency Blog CMS | 13/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) admin/plugins/NP_Poll.php; and allow remote authenticated users… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | F-art Agency Blog CMS | 6/7/2006 | 16/6/2026 | SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.4% | — | F-art Agency Blog CMSPunbb | 31/12/2005 | 16/6/2026 | PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header. |