Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1625 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%💥 ExploitPixel Motion Blog28/3/200616/6/2026
Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.
ModificadaMedia (4.3)5.3%💥 ExploitComoblog Project ComoblogEasymoblog24/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in img.php in (1) EasyMoblog 0.5.1 and (2) CoMoblog 1.1 allows remote attackers to inject arbitrary web script or HTML via the i parameter.
ModificadaMedia (5)2.2%—Oracle Weblogic Portal22/3/200616/6/2026
Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user.
ModificadaMedia (5)1.5%—BEA Weblogic Server22/3/200616/6/2026
BEA WebLogic Server 6.1 SP7 and earlier allows remote attackers to read arbitrary files via unknown attack vectors related to a "default internal servlet" accessed through HTTP.
ModificadaMedia (5)1.8%—BEA Weblogic Server22/3/200616/6/2026
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP6 and earlier, and WebLogic Server 6.1 SP7 and earlier allow remote attackers to cause a denial of service (memory exhaustion) via crafted non-canonicalized XML documents.
ModificadaMedia (6.4)2.4%💥 ExploitMaian Script World Maian Weblog21/3/200616/6/2026
Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php.
ModificadaMedia (6.4)3.6%💥 ExploitBetaparticle Blog21/3/200616/6/2026
Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.
ModificadaAlta (7.5)9.7%💥 ExploitAlexander Palmo Simple PHP Blog15/3/200616/6/2026
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache…
ModificadaMedia (4.3)2.9%💥 ExploitMywebland Mybloggie14/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message…
ModificadaMedia (4.3)1.2%—Ftpoed Blog Engine10/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in FTPoed Blog Engine 1.1 allows remote attackers to inject arbitrary web script or HTML via the comment_body parameter, as used by the comment field, when posting a comment.
ModificadaAlta (7.5)1.2%💥 ExploitRedblog10/3/200616/6/2026
SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
ModificadaMedia (4.3)2.0%💥 ExploitSblog10/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter to comments_do.php.
ModificadaAlta (10)2.0%💥 ExploitD2ksoft D2kblog9/3/200616/6/2026
SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.
ModificadaMedia (6.8)1.7%—D2ksoft D2kblog9/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in Default.asp in D2KBlog 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (6.4)3.3%💥 ExploitGerrit VAN Aaken Loudblog9/3/200616/6/2026
Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in the (1) template and (2) page parameters in (a) index.php, and the (3) language parameter in (b) inc/backend_settings.php.
ModificadaMedia (5)1.3%💥 ExploitGerrit VAN Aaken Loudblog9/3/200616/6/2026
SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.2%—Evo-dev Evoblog9/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter and (2) other unspecified parameters.
ModificadaAlta (7.5)2.6%💥 ExploitSmartblog7/3/200616/6/2026
PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.
ModificadaAlta (7.5)3.6%💥 ExploitArchangelmgt Weblog1/3/200616/6/2026
Archangel Weblog 0.90.02 permite a atacantes remotos eludir la autenticación estableciendo la cookie ba_admin a 1.
ModificadaMedia (6.5)1.3%—Archangelmgt Weblog1/3/200616/6/2026
Vulnerabilidad incluida en el archivo remoto PHP en admin/index.php en Archangel Weblog 0.90.02 permite a administradores remotos autenticados ejecutar código PHP arbitrario a través de una URL que termina en NULL (%00) en el parámetro index.
ModificadaAlta (7.5)1.7%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
ModificadaMedia (4.3)1.2%—Leif M. Wright WEB Blog22/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the…
ModificadaMedia (6.5)1.3%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
ModificadaMedia (5)1.4%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.
ModificadaMedia (4.3)1.3%—Perlblog19/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.