Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.87%—Laravel-bjyblog Project Laravel-bjyblog10/10/201917/6/2026
laravel-bjyblog 6.1.1 has XSS via a crafted URL.
ModificadaAlta (7.2)2.2%—Miniblog Project Miniblog14/6/201917/6/2026
madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in app_code/handlers/PostHandler.cs writes a decoded base64 string to a file without validating the extension.
ModificadaCrítica (9.8)2.8%—Print MY Blog Project Print MY Blog27/4/201917/6/2026
Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
ModificadaAlta (7.5)1.1%—Simply-blog Project Simply-blog1/1/201917/6/2026
Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter.
ModificadaCrítica (9.8)3.2%💥 ExploitSuper CMS Blog PRO Project Super CMS Blog PRO28/9/201817/6/2026
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
ModificadaMedia (5.4)0.48%—Complete Responsive CMS Blog Project Complete Responsive CMS Blog10/9/201817/6/2026
Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment.
ModificadaCrítica (9.8)1.2%—Zorovavi/blog Project Zorovavi/blog17/10/201717/6/2026
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
ModificadaCrítica (9.8)2.1%—Blog Project Blog12/9/201717/6/2026
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
ModificadaCrítica (9.8)1.1%—Blog Project Blog12/9/201717/6/2026
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.
ModificadaMedia (6.8)0.98%—Bblog Project Bblog8/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users.
ModificadaMedia (6.8)1.0%—Twitter Liveblog Project Twitter Liveblog31/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mashtlb_twitter_username parameter in the twitter-liveblog.php page…
ModificadaMedia (4.3)5.3%💥 ExploitComoblog Project ComoblogEasymoblog24/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
Orbitaley — Vulnerabilidades