Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Mafia Blog | 2/5/2005 | 16/6/2026 | Mafia Blog .4 BETA does not properly protect the admin directory, which allows remote attackers to execute arbitrary PHP code by using writeinfo.php to inject the code into info.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Ublog ReloadAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | ASP Press ACS Blog | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover or onload events in (1) img, (2) link, or (3) mail tags. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Betaparticle Blog | 2/5/2005 | 16/6/2026 | betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.4% | — | Uapplication Ublog Reload | 2/5/2005 | 16/6/2026 | Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | ASP Press ACS Blog | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (5) | 1.7% | — | Alexander Palmo Simple PHP Blog | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Eaden Mckee Bblog | 23/4/2005 | 16/6/2026 | SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |
| Modificada | Media (4.3) | 0.99% | — | Mywebland Mybloggie | 15/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments. | |
| Modificada | Media (5) | 1.5% | — | Sphpblog | 14/4/2005 | 16/6/2026 | Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files. | |
| Modificada | Alta (7.5) | 1.6% | — | Towerblog | 10/4/2005 | 16/6/2026 | TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file. | |
| Modificada | Media (4.6) | 8.1% | 💥 Exploit | Jason Hines Phpweblog | 7/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Blog Torrent Preview | 10/1/2005 | 16/6/2026 | Directory traversal vulnerability in btdownload.php in Blog Torrent preview 0.8 allows remote attackers to download arbitrary files via a .. (dot dot) in the file argument. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Korweblog | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Korweblog | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng… | |
| Modificada | Media (4.6) | 0.42% | — | BEA Weblogic Server | 31/12/2004 | 16/6/2026 | BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Leif M. Wright WEB Blog | 31/12/2004 | 16/6/2026 | blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests. | |
| Modificada | Baja (2.1) | 0.21% | — | BEA Weblogic Server | 31/12/2004 | 16/6/2026 | BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword. | |
| Modificada | Media (5.5) | 1.3% | — | BEA Weblogic Server | 31/12/2004 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, when using Remote Method Invocation (RMI) over Internet Inter-ORB Protocol (IIOP), does not properly handle when multiple logins for different users coming from the same client, which could cause an "unexpected user identity" to be used in an RMI call. | |
| Modificada | Alta (7.5) | 1.2% | — | Eaden Mckee Bblog | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter. | |
| Modificada | Media (5) | 1.8% | — | BEA Weblogic Server | 31/12/2004 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends. | |
| Modificada | Alta (7.5) | 1.5% | — | BEA Weblogic ServerAIBEA Weblogic ExpressAI | 31/12/2004 | 16/6/2026 | The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges. | |
| Modificada | Media (5) | 1.5% | — | Korweblog | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to read arbitrary files and execute arbitrary PHP files via .. (dot dot) sequences in the lng parameter. |