Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.46%—Perfreeblog1/5/202317/6/2026
Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function.
AnalizadaMedia (5.4)0.36%—Zhenfeng13 MY Blog1/5/202317/6/2026
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString.
AnalizadaMedia (5.4)0.41%—Zhenfeng13 MY Blog1/5/202317/6/2026
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
ModificadaAlta (7.5)0.84%—Oracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.…
ModificadaAlta (7.5)0.63%—Oracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful…
ModificadaAlta (7.5)0.84%—Oracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful…
ModificadaMedia (5.6)0.42%—Oracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks…
ModificadaMedia (6.1)0.41%—Oracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful…
ModificadaAlta (7.5)82%💥 PoCOracle Weblogic Server18/4/202317/6/2026
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful…
ModificadaMedia (6.5)0.85%—Mogublog Project Mogublog15/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The…
ModificadaMedia (4.3)0.33%—My-blog Project My-blog7/4/202317/6/2026
A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The…
ModificadaMedia (6.1)0.43%—Zblogcn Zblogphp4/4/202317/6/2026
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.
ModificadaCrítica (9.8)4.7%💥 ExploitXipblog Project Xipblog27/3/202317/6/2026
SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.
ModificadaCrítica (9.8)59%💥 ExploitJoommasters JMS Blog23/3/202317/6/2026
PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.
ModificadaCrítica (9.8)0.94%—Perfreeblog15/3/202317/6/2026
An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file.
ModificadaMedia (6.1)0.36%—My-blog Project My-blog13/3/202317/6/2026
Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function.
ModificadaMedia (5.3)0.43%—Blogengine.net6/3/202317/6/2026
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
ModificadaMedia (5.4)0.36%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post.
ModificadaMedia (5.4)0.38%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
ModificadaMedia (5.4)0.65%—Essentialplugin WP Blog AND Widget6/2/202317/6/2026
The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as…
ModificadaMedia (5.4)0.63%—Solwininfotech Blog Designer30/1/202317/6/2026
The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (5.4)0.44%—Infornweb News & Blog Designer Pack30/1/202317/6/2026
The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaCrítica (9.8)1.6%—Javaweb Blog Project Javaweb Blog26/1/202317/6/2026
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
ModificadaMedia (6.5)0.69%—Blog-ssm Project Blog-ssm26/1/202317/6/2026
An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.
ModificadaAlta (8.8)2.3%—Blog-ssm Project Blog-ssm26/1/202317/6/2026
File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escalated privileges via the /uploadFileList component.