Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1625 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.0%—Mywebland Mybloggie14/12/200516/6/2026
Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameters in adduser.php, (4) the post_id parameter in del.php, (5) the…
ModificadaAlta (7.5)1.1%💥 ExploitPluggedout Blog7/12/200516/6/2026
SQL injection vulnerability in index.php in PluggedOut Blog 1.9.5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categoryid, (2) entryid, (3) year, (4) month, and (5) day parameter.
ModificadaAlta (7.5)1.2%—Saralblog7/12/200516/6/2026
SQL injection vulnerability in saralblog 1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to viewprofile.php.
ModificadaAlta (7.5)2.3%💥 ExploitNetart Media Blog System7/12/200516/6/2026
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.
ModificadaAlta (7.5)1.4%💥 ExploitGreywyvern Orca Blog1/12/200516/6/2026
SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.
ModificadaMedia (4.3)4.4%💥 ExploitBlogbuddies1/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in blogBuddies 0.3 allows remote attackers to inject arbitrary web script or HTML via the u parameter to index.php.
ModificadaMedia (4.3)5.6%💥 ExploitBlogbuddiesJawsMagpierss1/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in MagpieRSS 7.1, as used in (a) blogBuddiesv 0.3, (b) Jaws 0.6.2, and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) magpie_debug.php and (2) rss_url parameter to (b) magpie_slashbox.php and…
ModificadaAlta (7.5)1.6%—Ar-blog4/11/200516/6/2026
Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying cookies.
ModificadaMedia (4.3)1.3%—Ar-blog4/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog comment.
ModificadaMedia (4.3)2.2%💥 ExploitAlexander Palmo Simple PHP Blog3/11/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)…
ModificadaMedia (4.3)1.2%—Sparkleblog30/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.
ModificadaMedia (4.3)1.3%—Zeroblog20/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in thread.php for Zeroblog 1.1f and 1.2a allows remote attackers to inject arbitrary web script or HTML via the threadID parameter.
ModificadaAlta (7.5)1.5%—Mywebland Mybloggie5/10/200516/6/2026
login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than…
ModificadaAlta (7.5)1.4%—Mywebland Mybloggie7/9/200516/6/2026
SQL injection vulnerability in login.php in myBloggie 2.1.3-beta and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (5)5.6%💥 ExploitAlexander Palmo Simple PHP Blog2/9/200516/6/2026
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
ModificadaAlta (7.5)51%💥 ExploitAlexander Palmo Simple PHP Blog30/8/200516/6/2026
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
ModificadaMedia (4.3)1.8%💥 ExploitFoojan PHP Weblog30/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.
ModificadaMedia (5)1.2%—Foojan PHP Weblog30/8/200516/6/2026
Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.
ModificadaMedia (5)3.4%—Oracle Weblogic Portal23/8/200516/6/2026
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.
ModificadaMedia (4.3)1.4%💥 ExploitApple Weblog ServerApple MAC OS X19/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaAlta (7.5)2.7%💥 ExploitBlog Torrent12/7/200516/6/2026
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated using data/newusers.
ModificadaMedia (5)4.1%💥 ExploitAlexander Palmo Simple PHP Blog11/7/200516/6/2026
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
ModificadaMedia (4.3)1.5%—BEA Weblogic Server5/7/200516/6/2026
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the…
ModificadaMedia (4.3)3.6%💥 ExploitUapplication Ublog Reload20/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in trackback.asp in Ublog Reload 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the btitle parameter.
ModificadaAlta (7.5)1.2%💥 ExploitUblog Reload20/6/200516/6/2026
Multiple SQL injection vulnerabilities in Ublog Reload 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) ci, (2) d, or (3) m parameter to index.asp, or the (4) bi parameter to blog_comment.asp.
Orbitaley — Vulnerabilidades