Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
151 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Brewblogger | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in printLog.php in BrewBlogger (BB) 1.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 1.6% | — | Nmnlogger | 1/11/2006 | 16/6/2026 | Unspecified vulnerability in NmnLogger 1.0.0 and earlier has unknown impact and attack vectors related to configuration of mesasge drivers. | |
| Modificada | Alta (7.5) | 1.5% | — | Comdev WEB Blogger | 20/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Alta (7.5) | 1.3% | — | Dimitri Seitz Security Suite IP Logger | 17/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) mkb.php, (2) iplogger.php, (3) admin_board2.php, or (4) admin_logger.php in includes/, different… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Dimitri Seitz Security Suite IP Logger | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | JL Webworks Quickblogger | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in acc.php in QuickBlogger (QB) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (4.3) | 2.5% | — | Roller Weblogger | 19/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Roller WebLogger 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) url parameters; (4) certain content parameters in the preview method; or (5) the q parameter in (a) sitesearch.do. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Icblogger | 7/9/2006 | 16/6/2026 | SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the YID parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Phpblogger Php-blogger | 11/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters. | |
| Modificada | Media (5.8) | 1.0% | — | Iplogger | 25/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the HTTP_REFERER header in an HTTP request. | |
| Modificada | Media (5.8) | 1.3% | — | Iplogger | 24/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or web script via the User-Agent (useragent) header in an HTTP request, which is not filtered when the log files are viewed. | |
| Modificada | Alta (7.5) | 1.1% | — | Plogger | 3/5/2006 | 16/6/2026 | SQL injection vulnerability in gallery.php in Plogger Beta 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter, when the level is set to "slideshow". NOTE: This is a different vulnerability than CVE-2005-4246. | |
| Modificada | Alta (7.5) | 1.8% | — | JL Webworks Quickblogger | 14/4/2006 | 16/6/2026 | Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Mike Helton Aoblogger | 19/1/2006 | 16/6/2026 | create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Tanklogger | 14/1/2006 | 16/6/2026 | SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php. | |
| Modificada | Media (4.3) | 1.4% | — | JL Webworks Quickblogger | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Plogger | 29/12/2005 | 16/6/2026 | PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Plogger | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in Plogger Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php and (2) page parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Plogger | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Plogger Beta 2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchterms parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Babe Logger | 30/11/2005 | 16/6/2026 | SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php. | |
| Modificada | Media (5) | 1.8% | — | Nanoblogger | 19/6/2005 | 16/6/2026 | Unknown vulnerability in "various plugins" for NanoBlogger 3.2.1 and earlier allows remote attackers to execute arbitrary commands. | |
| Modificada | Alta (7.5) | 1.2% | — | Newlife Blogger | 1/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Powerphlogger | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in showhits.php3 for PowerPhlogger (PPhlogger) 2.0.9 through 2.2.2 allows remote attackers to execute arbitrary PHP code via the rel_path parameter. |