Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Graviton-mediatech Visitor Logger | 3/6/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter. | |
| Modificada | Media (5) | 1.1% | — | Phpee Pphlogger | 10/12/2009 | 16/6/2026 | PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpee Pphlogger | 10/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Brewblogger | 6/8/2009 | 16/6/2026 | SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Comdev WEB Blogger | 23/2/2009 | 16/6/2026 | SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Newlife Blogger | 19/2/2009 | 16/6/2026 | SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 3/2/2009 | 16/6/2026 | Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Parsblogger | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter. | |
| Modificada | Alta (7.2) | 0.93% | 💥 Exploit | Isecsoft Anti-keylogger Elite | 13/11/2008 | 16/6/2026 | Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL. | |
| Modificada | Alta (9.3) | 18% | 💥 Exploit | Microsoft Windows Image Acquisition Logger | 11/9/2008 | 16/6/2026 | The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Plogger | 10/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Chipmunk Scripts Chipmunk Blogger | 15/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (6.5) | 0.90% | 💥 Exploit | Powerphlogger | 6/6/2008 | 16/6/2026 | SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Nilsons Blogger | 4/2/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Plogger | 28/12/2007 | 16/6/2026 | SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Httplogger | 11/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.3% | — | Phpblogger Php-blogger | 3/8/2007 | 16/6/2026 | PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication… | |
| Modificada | Alta (7.5) | 1.4% | — | Phpee Power Phlogger | 26/6/2007 | 16/6/2026 | SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Particle Blogger | 11/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in archives.php in Particle Blogger 1.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the month parameter and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Comdev WEB Blogger | 6/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different vector than CVE-2006-5441. | |
| Modificada | Alta (7.5) | 1.4% | — | Plogger | 25/4/2007 | 16/6/2026 | Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Particle Blogger | 20/3/2007 | 16/6/2026 | SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Powerphlogger | 3/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter. | |
| Modificada | Baja (3.5) | 0.89% | — | Chipmunk Scripts Chipmunk Blogger | 24/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery. |