Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Mywebland Mybloggie | 14/12/2005 | 16/6/2026 | Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Pluggedout Blog | 7/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Saralblog | 7/12/2005 | 16/6/2026 | SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Netart Media Blog System | 7/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Greywyvern Orca Blog | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter. | |
| Modificada | Media (4.3) | 4.4% | 💥 Exploit | Blogbuddies | 1/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | BlogbuddiesJawsMagpierss | 1/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and… | |
| Modificada | Alta (7.5) | 1.6% | — | Ar-blog | 4/11/2005 | 16/6/2026 | Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying cookies. | |
| Modificada | Media (4.3) | 1.3% | — | Ar-blog | 4/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog comment. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 3/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)… | |
| Modificada | Media (4.3) | 1.2% | — | Sparkleblog | 30/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field. | |
| Modificada | Media (4.3) | 1.3% | — | Zeroblog | 20/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog 1.1f and 1.2a allows remote attackers to inject arbitrary web script or HTML via the threadID parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Mywebland Mybloggie | 5/10/2005 | 16/6/2026 | login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than… | |
| Modificada | Alta (7.5) | 1.4% | — | Mywebland Mybloggie | 7/9/2005 | 16/6/2026 | SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (5) | 5.6% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 2/9/2005 | 16/6/2026 | comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter. | |
| Modificada | Alta (7.5) | 51% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 30/8/2005 | 16/6/2026 | upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Foojan PHP Weblog | 30/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header. | |
| Modificada | Media (5) | 1.2% | — | Foojan PHP Weblog | 30/8/2005 | 16/6/2026 | Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message. | |
| Modificada | Media (5) | 3.4% | — | Oracle Weblogic Portal | 23/8/2005 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Apple Weblog ServerApple MAC OS X | 19/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Blog Torrent | 12/7/2005 | 16/6/2026 | Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers. | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 11/7/2005 | 16/6/2026 | SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack. | |
| Modificada | Media (4.3) | 1.5% | — | BEA Weblogic Server | 5/7/2005 | 16/6/2026 | BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the… | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Uapplication Ublog Reload | 20/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ublog Reload | 20/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp. |