Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.36% | — | Wpwebelite Follow MY Blog Post | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Retrieve Embedded Sensitive Data.This issue affects Follow My Blog Post: from n/a through <= 2.3.9. | |
| Analizada | Baja (2.1) | 0.34% | — | Philipinho Simple-php-blog | 8/12/2025 | 17/6/2026 | A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown processing of the file /edit.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be… | |
| Analizada | Baja (2.1) | 0.63% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file /networkDisk/unzipFile of the component ZIP File Handler. Such manipulation of the argument fileUrl leads to path traversal. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.38% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestricted upload. The attack may be initiated remotely. The exploit has been made available to the public and could be… | |
| Analizada | Media (5.5) | 0.53% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may… | |
| Analizada | Baja (2.9) | 0.47% | — | Mogublog Project Mogublog | 1/12/2025 | 25/9/2026 | A vulnerability was identified in moxi159753 Mogu Blog v2 up to 5.2. This issue affects some unknown processing of the file /storage/ of the component Storage Management Endpoint. The manipulation leads to missing authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The… | |
| Aplazada | Media (5.4) | 0.25% | — | Adenion Blog2socialAI | 25/11/2025 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Baja (2.1) | 0.29% | — | Fabian Blog Site | 24/11/2025 | 17/6/2026 | A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /admin.php. Performing manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit is now public and may be used. Multiple endpoints are affected. | |
| Analizada | Baja (2.1) | 0.29% | — | Fabian Blog Site | 24/11/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of the file /resources/functions/blog.php of the component Category Handler. Such manipulation of the argument name/field leads to sql injection. The attack may be performed from remote. The exploit has… | |
| Analizada | Crítica (9.8) | 0.49% | — | 2dogz Blogin | 20/11/2025 | 17/6/2026 | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (2025-01-13). A weak verification code generation mechanism combined with missing rate limiting allows attackers to perform brute-force attacks on verification codes without authentication. Successful… | |
| Aplazada | Media (4.3) | 0.12% | — | WP Admin MicroblogAI | 18/11/2025 | 17/6/2026 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf of an administrator… | |
| Analizada | Media (6.2) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations. | |
| Analizada | Alta (7.1) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive… | |
| Analizada | Baja (2) | 0.26% | — | H3blog | 14/11/2025 | 17/6/2026 | A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Modificada | Baja (2) | 0.26% | — | H3blog | 14/11/2025 | 17/6/2026 | A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/material/add. Executing a manipulation of the argument Name can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (4.3) | 0.21% | — | Adenion Blog2socialAI | 6/11/2025 | 17/6/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 8.6.0 via the getFullContent() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to… | |
| Aplazada | Media (4.3) | 0.19% | — | Adenion Blog2socialAI | 6/11/2025 | 1/10/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Media (6.5) | 0.26% | — | Perfreeblog | 30/10/2025 | 17/6/2026 | PerfreeBlog v4.0.11 is vulnerable to Server-Side Request Forgery due to a missing authorization check in the uploadAttachByUrl API endpoint (AttachController.java). | |
| Aplazada | Media (5.3) | 0.27% | — | Solwin Blog Designer PROAI | 29/10/2025 | 5/10/2026 | Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8. | |
| Modificada | Crítica (9.8) | 0.49% | — | Zhyd Oneblog | 28/10/2025 | 17/6/2026 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | |
| Aplazada | Alta (7.5) | 0.26% | — | Blog-vue-springbootAI | 28/10/2025 | 17/6/2026 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. | |
| Analizada | Baja (2.1) | 0.51% | — | Quequnlong Shiyi-blog | 27/10/2025 | 17/6/2026 | A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserialization. The attack can be executed remotely. The exploit has been made public and… | |
| Aplazada | Media (4.3) | 0.14% | — | Clifton Griffin Simple Content Templates FOR Blog Posts AND PagesAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for Blog Posts & Pages simple-post-template allows Cross Site Request Forgery.This issue affects Simple Content Templates for Blog Posts & Pages: from n/a through <= 2.2.61. | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function | |
| Modificada | Alta (7.6) | 0.27% | — | Perfreeblog | 24/10/2025 | 5/7/2026 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function |