Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phpeasynews Phpeasyblog | 23/6/2008 | 16/6/2026 | SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Y-blog Yblog | 12/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Y-blog Yblog | 12/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mywebland Mybloggie | 12/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE:… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mywebland Mybloggie | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225. | |
| Modificada | Media (6.8) | 1.4% | — | Wikyblog | 21/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in include/sessionRegister.php in WikyBlog before 1.4.13 allows remote attackers to inject arbitrary web script or HTML, probably via vectors related to a certain data2 array element. | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Myblog | 18/4/2007 | 16/6/2026 | MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php. | |
| Modificada | Media (6.5) | 1.2% | — | Myblog | 18/4/2007 | 16/6/2026 | Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by… | |
| Modificada | Alta (7.5) | 1.2% | — | SAM Crew Myblog | 12/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter. | |
| Modificada | Media (4.3) | 0.89% | — | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Mywebland Mybloggie | 19/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string. | |
| Modificada | Media (6.8) | 1.1% | — | Wikyblog | 11/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WBmap.php in WikyBlog 1.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) key, (2) d, (3) l, or (4) v parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.5) | 1.5% | — | Wikyblog | 11/12/2006 | 16/6/2026 | Directory traversal vulnerability in WBmap.php in WikyBlog 1.3.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter. NOTE: CVE disputes this vulnerability because l is validated by ctype_alpha before use | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Wikyblog | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Yblog | 5/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php. | |
| Modificada | Media (5) | 1.7% | — | Mywebland Mybloggie | 9/8/2006 | 16/6/2026 | index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Mywebland Mybloggie | 9/8/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Mywebland Mybloggie | 27/7/2006 | 16/6/2026 | SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote attackers to execute arbitrary SQL commands via the (1) post_id parameter in index.php and (2) search function. | |
| Modificada | Media (5.8) | 2.1% | — | Mywebland Mybloggie | 27/7/2006 | 16/6/2026 | CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie. | |
| Modificada | Alta (7.5) | 1.8% | — | Mywebland Mybloggie | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in MyBloggie 2.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mybloggie_root_path parameter to (1) admin.php or (2) scode.php. NOTE: this issue has been disputed in multiple third party followups, which say that the MyBloggie source code… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mywebland Mybloggie | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Mywebland Mybloggie | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message… | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Cheesyblog | 26/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment. | |
| Modificada | Alta (7.5) | 2.0% | — | Mywebland Mybloggie | 14/12/2005 | 16/6/2026 | Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the… |