Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Pixelpost Photoblog | 25/1/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php en Pixelpost Photoblog 1.4.3 permite a atacantes remotos inyectar 'script' web de su elección o HTML mediante el campo "Añadir Comentario" en una ventana emergente de comentario. | |
| Modificada | Media (5) | 1.8% | — | Mike Macgirvin Note-a-day Weblog | 25/1/2006 | 16/6/2026 | Note-A-Day Weblog 2.2 almacena información sensible bajo la raíz de documentos web con control de acceso insuficiente, lo que permite a atacantes remotos obtener información sensible mediante una petición diferente a archive/.phpass-admin, que contiene contraseñas cifradas. | |
| Modificada | Alta (7.5) | 2.0% | — | E-moblog | 25/1/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en e-moBLOG 1.3 permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) "monthy" de index.php o el parámetro (2) "login" de admin/index.php. NOTA: Algunas fuentes han informado que el artículo (1) implica el parámetro "monthly", pero… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Insane Visions Blogphp | 22/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie. | |
| Modificada | Media (5) | 1.8% | — | Noah Medling Rcblog | 22/1/2006 | 16/6/2026 | Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | BIT 5 Blog | 22/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>. | |
| Modificada | Media (5) | 2.9% | — | Noah Medling Rcblog | 22/1/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Saral Kaushik Saralblog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is not properly handled in the comment function in functions.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Saral Kaushik Saralblog | 21/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. | |
| Modificada | Media (4.3) | 1.2% | — | Ar-blog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Webspotblogging | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Insane Visions Blogphp | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | BIT 5 Blog | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Bitdamaged Geoblog | 18/1/2006 | 16/6/2026 | SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable). | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | 8pixel.net Simple Blog | 18/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts. | |
| Modificada | Media (5.8) | 1.5% | — | 8pixel.net Simple Blog | 18/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts. | |
| Modificada | Media (4.3) | 1.2% | — | Microblog | 18/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in functions.php in microBlog 2.0 RC-10 allows remote attackers to inject arbitrary web script and HTML via a javascript: URI in a [url] BBcode tag. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Microblog | 18/1/2006 | 16/6/2026 | SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Sblog | 6/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in sBLOG 0.7.1 Beta 20051202 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p and (2) keyword parameters in (a) index.php and (b) search.php. | |
| Modificada | Media (5) | 1.8% | — | BEA Weblogic Server | 31/12/2005 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allow remote attackers to obtain sensitive information (intranet IP addresses) via unknown attack vectors involving "network address translation." |