Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.46% | — | Perfreeblog | 1/5/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in PerfreeBlog 3.1.2 allows attackers to execute arbitrary code via the Post function. | |
| Analizada | Media (5.4) | 0.36% | — | Zhenfeng13 MY Blog | 1/5/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString. | |
| Analizada | Media (5.4) | 0.41% | — | Zhenfeng13 MY Blog | 1/5/2023 | 17/6/2026 | Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString. | |
| Modificada | Alta (7.5) | 0.84% | — | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Modificada | Alta (7.5) | 0.63% | — | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (7.5) | 0.84% | — | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Media (5.6) | 0.42% | — | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks… | |
| Modificada | Media (6.1) | 0.41% | — | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Alta (7.5) | 82% | 💥 PoC | Oracle Weblogic Server | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful… | |
| Modificada | Media (6.5) | 0.85% | — | Mogublog Project Mogublog | 15/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal. The attack may be initiated remotely. The… | |
| Modificada | Media (4.3) | 0.33% | — | My-blog Project My-blog | 7/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in zhenfeng13 My-Blog. Affected is an unknown function of the file /admin/configurations/userInfo. The manipulation of the argument yourAvatar/yourName/yourEmail leads to cross-site request forgery. It is possible to launch the attack remotely. The… | |
| Modificada | Media (6.1) | 0.43% | — | Zblogcn Zblogphp | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model. | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Xipblog Project Xipblog | 27/3/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Joommasters JMS Blog | 23/3/2023 | 17/6/2026 | PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Crítica (9.8) | 0.94% | — | Perfreeblog | 15/3/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the /admin/user/uploadImg component of PerfreeBlog v3.1.1 allows attackers to execute arbitrary code via a crafted JPG file. | |
| Modificada | Media (6.1) | 0.36% | — | My-blog Project My-blog | 13/3/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in My-Blog allows attackers to cause a denial of service via the Post function. | |
| Modificada | Media (5.3) | 0.43% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs. | |
| Modificada | Media (5.4) | 0.36% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post. | |
| Modificada | Media (5.4) | 0.38% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file. | |
| Modificada | Media (5.4) | 0.65% | — | Essentialplugin WP Blog AND Widget | 6/2/2023 | 17/6/2026 | The WP Blog and Widgets WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (5.4) | 0.63% | — | Solwininfotech Blog Designer | 30/1/2023 | 17/6/2026 | The Blog Designer WordPress plugin before 2.4.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Media (5.4) | 0.44% | — | Infornweb News & Blog Designer Pack | 30/1/2023 | 17/6/2026 | The News & Blog Designer Pack WordPress plugin before 3.3 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. | |
| Modificada | Crítica (9.8) | 1.6% | — | Javaweb Blog Project Javaweb Blog | 26/1/2023 | 17/6/2026 | An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile. | |
| Modificada | Media (6.5) | 0.69% | — | Blog-ssm Project Blog-ssm | 26/1/2023 | 17/6/2026 | An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component. | |
| Modificada | Alta (8.8) | 2.3% | — | Blog-ssm Project Blog-ssm | 26/1/2023 | 17/6/2026 | File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escalated privileges via the /uploadFileList component. |