Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.8%💥 ExploitGraviton-mediatech Visitor Logger3/6/201016/6/2026
PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter.
ModificadaMedia (5)1.1%—Phpee Pphlogger10/12/200916/6/2026
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.php, (5) head_stuff.inc.php, (6) loglist.inc.php, and (7) pphlogger_send.inc.php in include/, which reveals the installation path in an error…
ModificadaMedia (4.3)1.5%💥 ExploitPhpee Pphlogger10/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.
ModificadaMedia (6.8)2.0%💥 ExploitBrewblogger6/8/200916/6/2026
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are…
ModificadaMedia (6.8)1.1%💥 ExploitComdev WEB Blogger23/2/200916/6/2026
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
ModificadaAlta (7.5)1.7%💥 ExploitNewlife Blogger19/2/200916/6/2026
SQL injection vulnerability in system/nlb_user.class.php in NewLife Blogger 3.0 and earlier, and possibly 3.3.1, allows remote attackers to execute arbitrary SQL commands via the nlb3 cookie.
ModificadaAlta (7.5)1.1%💥 ExploitChipmunk Scripts Chipmunk Blogger3/2/200916/6/2026
SQL injection vulnerability in admin/authenticate.php in Chipmunk Blogger Script allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)2.3%💥 ExploitChipmunk Scripts Chipmunk Blogger3/2/200916/6/2026
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administrator does not properly follow installation directions.
ModificadaAlta (7.5)2.0%💥 ExploitParsblogger17/12/200816/6/2026
SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands via the wr parameter.
ModificadaAlta (7.2)0.93%💥 ExploitIsecsoft Anti-keylogger Elite13/11/200816/6/2026
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other versions including 3.3.3, allows local users to gain privileges via long inputs to the (1) 0x002224A4, (2) 0x002224C0, and (3) 0x002224CC IOCTL.
ModificadaAlta (9.3)18%💥 ExploitMicrosoft Windows Image Acquisition Logger11/9/200816/6/2026
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this…
ModificadaAlta (7.5)2.4%💥 ExploitPlogger10/8/200816/6/2026
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the checked array parameter to plog-download.php in an album action and (2) unspecified parameters to plog-remote.php, and (3) allow remote authenticated administrators to execute…
ModificadaMedia (4.3)1.2%💥 ExploitChipmunk Scripts Chipmunk Blogger15/7/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the…
ModificadaMedia (6.5)0.90%💥 ExploitPowerphlogger6/6/200816/6/2026
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.
ModificadaMedia (5)2.7%💥 ExploitNilsons Blogger4/2/200816/6/2026
Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.
ModificadaAlta (7.5)3.4%💥 ExploitPlogger28/12/200716/6/2026
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.7%—Httplogger11/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in HttpLogger 0.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)2.3%—Phpblogger Php-blogger3/8/200716/6/2026
PHPBlogger stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing an admin password hash via a direct request for data/pref.db. NOTE: this can be easily leveraged for administrative access because composing the authentication…
ModificadaAlta (7.5)1.4%—Phpee Power Phlogger26/6/200716/6/2026
SQL injection vulnerability in include/get_userdata.php in Power Phlogger (PPhlogger) 2.2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to login.php.
ModificadaAlta (7.5)1.1%—Particle Blogger11/6/200716/6/2026
Multiple SQL injection vulnerabilities in archives.php in Particle Blogger 1.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the month parameter and other unspecified vectors.
ModificadaAlta (7.5)1.3%—Comdev WEB Blogger6/6/200716/6/2026
PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different vector than CVE-2006-5441.
ModificadaAlta (7.5)1.4%—Plogger25/4/200716/6/2026
Session fixation vulnerability in Plogger allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
ModificadaAlta (7.5)2.0%💥 ExploitParticle Blogger20/3/200716/6/2026
SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
ModificadaAlta (7.5)2.3%💥 ExploitPowerphlogger3/3/200716/6/2026
PHP remote file inclusion vulnerability in config.inc.php3 in Power Phlogger 2.0.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.
ModificadaBaja (3.5)0.89%—Chipmunk Scripts Chipmunk Blogger24/2/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.
Orbitaley — Vulnerabilidades