Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1625 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Mafia Blog2/5/200516/6/2026
Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php.
ModificadaAlta (7.5)1.3%—Invision Power Services Invision Community Blog2/5/200516/6/2026
SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.
ModificadaMedia (4.3)2.0%💥 ExploitUblog ReloadAI2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (4.3)1.7%💥 ExploitASP Press ACS Blog2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags.
ModificadaMedia (5)3.5%💥 ExploitBetaparticle Blog2/5/200516/6/2026
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.
ModificadaMedia (4.3)1.7%💥 ExploitAlexander Palmo Simple PHP Blog2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)1.4%—Uapplication Ublog Reload2/5/200516/6/2026
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.
ModificadaMedia (4.3)1.9%💥 ExploitASP Press ACS Blog2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.
ModificadaMedia (5)1.7%—Alexander Palmo Simple PHP Blog2/5/200516/6/2026
Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.
ModificadaAlta (7.5)1.3%—Eaden Mckee Bblog23/4/200516/6/2026
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
ModificadaMedia (4.3)0.99%—Mywebland Mybloggie15/4/200516/6/2026
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.
ModificadaMedia (5)1.5%—Sphpblog14/4/200516/6/2026
Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.
ModificadaAlta (7.5)1.6%—Towerblog10/4/200516/6/2026
TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.
ModificadaMedia (4.6)8.1%💥 ExploitJason Hines Phpweblog7/3/200516/6/2026
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.
ModificadaMedia (5)3.2%💥 ExploitBlog Torrent Preview10/1/200516/6/2026
Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument.
ModificadaMedia (5)7.1%💥 ExploitKorweblog31/12/200416/6/2026
Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
ModificadaAlta (7.5)1.7%—Korweblog31/12/200416/6/2026
PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng…
ModificadaMedia (4.6)0.42%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.
ModificadaAlta (7.5)9.9%💥 ExploitLeif M. Wright WEB Blog31/12/200416/6/2026
blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.
ModificadaBaja (2.1)0.21%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
ModificadaMedia (5.5)1.3%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call.
ModificadaAlta (7.5)1.2%—Eaden Mckee Bblog31/12/200416/6/2026
SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter.
ModificadaMedia (5)1.8%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.
ModificadaAlta (7.5)1.5%—BEA Weblogic ServerAIBEA Weblogic ExpressAI31/12/200416/6/2026
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.
ModificadaMedia (5)1.5%—Korweblog31/12/200416/6/2026
Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter.