Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Pixel Motion Blog | 28/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Comoblog Project ComoblogEasymoblog | 24/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter. | |
| Modificada | Media (5) | 2.2% | — | Oracle Weblogic Portal | 22/3/2006 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user. | |
| Modificada | Media (5) | 1.5% | — | BEA Weblogic Server | 22/3/2006 | 16/6/2026 | BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal servlet" accessed through HTTP. | |
| Modificada | Media (5) | 1.8% | — | BEA Weblogic Server | 22/3/2006 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via crafted non-canonicalized XML documents. | |
| Modificada | Media (6.4) | 2.4% | 💥 Exploit | Maian Script World Maian Weblog | 21/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php. | |
| Modificada | Media (6.4) | 3.6% | 💥 Exploit | Betaparticle Blog | 21/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 15/3/2006 | 16/6/2026 | Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache… | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Mywebland Mybloggie | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message… | |
| Modificada | Media (4.3) | 1.2% | — | Ftpoed Blog Engine | 10/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Redblog | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Sblog | 10/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter to comments_do.php. | |
| Modificada | Alta (10) | 2.0% | 💥 Exploit | D2ksoft D2kblog | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie. | |
| Modificada | Media (6.8) | 1.7% | — | D2ksoft D2kblog | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (6.4) | 3.3% | 💥 Exploit | Gerrit VAN Aaken Loudblog | 9/3/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in the (1) template and (2) page parameters in (a) index.php, and the (3) language parameter in (b) inc/backend_settings.php. | |
| Modificada | Media (5) | 1.3% | 💥 Exploit | Gerrit VAN Aaken Loudblog | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Evo-dev Evoblog | 9/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Smartblog | 7/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Archangelmgt Weblog | 1/3/2006 | 16/6/2026 | Archangel Weblog 0.90.02 permite a atacantes remotos eludir la autenticación estableciendo la cookie ba_admin a 1. | |
| Modificada | Media (6.5) | 1.3% | — | Archangelmgt Weblog | 1/3/2006 | 16/6/2026 | Vulnerabilidad incluida en el archivo remoto PHP en admin/index.php en Archangel Weblog 0.90.02 permite a administradores remotos autenticados ejecutar código PHP arbitrario a través de una URL que termina en NULL (%00) en el parámetro index. | |
| Modificada | Alta (7.5) | 1.7% | — | Leif M. Wright WEB Blog | 22/2/2006 | 16/6/2026 | Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie. | |
| Modificada | Media (4.3) | 1.2% | — | Leif M. Wright WEB Blog | 22/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the… | |
| Modificada | Media (6.5) | 1.3% | — | Leif M. Wright WEB Blog | 22/2/2006 | 16/6/2026 | Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname. | |
| Modificada | Media (5) | 1.4% | — | Leif M. Wright WEB Blog | 22/2/2006 | 16/6/2026 | Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password. | |
| Modificada | Media (4.3) | 1.3% | — | Perlblog | 19/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters. |