Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.38% | — | Zblogcn ZblogphpAI | 20/4/2026 | 17/6/2026 | A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/AppCentre/app_upload.php of the component ZBA File Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used. The… | |
| Aplazada | Media (5.5) | 0.47% | — | Mogublog Mogu BlogAI | 20/4/2026 | 17/6/2026 | A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the function LocalFileServiceImpl.uploadPictureByUrl of the file mogu_picture/src/main/java/com/moxi/mogublog/picture/service/impl/LocalFileServiceImpl.java of the component Picture Storage Service. The… | |
| Aplazada | Baja (1.3) | 0.39% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Aplazada | Baja (2.9) | 0.42% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remotely. The attack… | |
| Aplazada | Baja (2.1) | 0.35% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.47% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.72% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used… | |
| Aplazada | Baja (2.9) | 0.40% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The attack requires a… | |
| Aplazada | Media (5.5) | 0.65% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 2.4% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injection. It is possible to launch the… | |
| Aplazada | Baja (2.1) | 0.32% | — | Code-projects Easy Blog SiteAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. | |
| Aplazada | Alta (8.8) | 0.59% | — | Buddypress GroupblogAI | 11/4/2026 | 17/6/2026 | The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.9.3. This is due to the group blog settings handler accepting the `groupblog-blogid`, `default-member`, and `groupblog-silent-add` parameters from user input without proper authorization checks.… | |
| Aplazada | Baja (2) | 0.33% | — | Code-projects Easy Blog SiteAI | 8/4/2026 | 24/7/2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the file /posts/update.php. The manipulation of the argument postTitle leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Easy Blog SiteAI | 8/4/2026 | 24/7/2026 | A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.3) | 0.26% | — | Themebeez Cream BlogAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in themebeez Cream Blog cream-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cream Blog: from n/a through <= 2.1.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Themegoods Grand BlogAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: from n/a through <= 3.1. | |
| Aplazada | Media (6.5) | 0.22% | — | Awplife Blog FilterAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Blog Filter blog-filter allows DOM-Based XSS.This issue affects Blog Filter: from n/a through <= 1.7.6. | |
| Aplazada | Media (4.3) | 0.49% | — | Adenion Blog2socialAI | 8/4/2026 | 24/7/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass through user-controlled key in all versions up to, and including, 8.8.3. This is due to the plugin's AJAX handlers failing to validate that the user-supplied 'b2s_id' parameter belongs to the current user… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Easy Blog SiteAI | 6/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Modificada | Media (4.3) | 0.33% | — | Anjoy8 Blog.admin | 27/3/2026 | 2/7/2026 | In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive data exposure. Unauthorized parties can obtain sensitive administrator account information via a valid token, threatening system security. NOTE: Blog.Admin is related front-end code that does not… | |
| Aplazada | Media (4.3) | 0.43% | — | Adenion Blog2socialAI | 26/3/2026 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all versions up to, and including, 8.8.2. This is due to the resetSocialMetaTags() function only verifying that the user has the 'read' capability and a valid b2s_security_nonce, both of which are… | |
| Aplazada | Baja (1.9) | 0.35% | — | Bolo BlogAI | 24/3/2026 | 17/6/2026 | A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulation of the argument articleTitle results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.4) | 0.23% | — | Riverforest-wp Simple Blog CardAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue affects Simple Blog Card: from n/a through <= 2.37. | |
| Analizada | Media (6.9) | 0.16% | — | Tomalofficial PHP OOP CMS Blog | 6/3/2026 | 17/6/2026 | OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by crafting malicious POST requests. Attackers can submit forms to the addUser.php endpoint with parameters including userName, password, email, and role set to… | |
| Analizada | Alta (8.8) | 0.37% | — | Tomalofficial PHP OOP CMS Blog | 6/3/2026 | 17/6/2026 | OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to… |