Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.87% | — | Laravel-bjyblog Project Laravel-bjyblog | 10/10/2019 | 17/6/2026 | laravel-bjyblog 6.1.1 has XSS via a crafted URL. | |
| Modificada | Alta (7.2) | 2.2% | — | Miniblog Project Miniblog | 14/6/2019 | 17/6/2026 | madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element with a data: URL, because SaveFilesToDisk in app_code/handlers/PostHandler.cs writes a decoded base64 string to a file without validating the extension. | |
| Modificada | Crítica (9.8) | 2.8% | — | Print MY Blog Project Print MY Blog | 27/4/2019 | 17/6/2026 | Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Simply-blog Project Simply-blog | 1/1/2019 | 17/6/2026 | Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Super CMS Blog PRO Project Super CMS Blog PRO | 28/9/2018 | 17/6/2026 | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | |
| Modificada | Media (5.4) | 0.48% | — | Complete Responsive CMS Blog Project Complete Responsive CMS Blog | 10/9/2018 | 17/6/2026 | Complete Responsive CMS Blog through 2018-05-20 has XSS via a comment. | |
| Modificada | Crítica (9.8) | 1.2% | — | Zorovavi/blog Project Zorovavi/blog | 17/10/2017 | 17/6/2026 | SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Blog Project Blog | 12/9/2017 | 17/6/2026 | upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file. | |
| Modificada | Crítica (9.8) | 1.1% | — | Blog Project Blog | 12/9/2017 | 17/6/2026 | SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php. | |
| Modificada | Media (6.8) | 0.98% | — | Bblog Project Bblog | 8/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (6.8) | 1.0% | — | Twitter Liveblog Project Twitter Liveblog | 31/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mashtlb_twitter_username parameter in the twitter-liveblog.php page… | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Comoblog Project ComoblogEasymoblog | 24/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter. |