Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
190 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Themebeans Blooog Theme | 17/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the jQuery parameter to assets/js/jplayer.swf. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Bloofoxcms | 7/10/2011 | 16/6/2026 | SQL injection vulnerability in index.php in BloofoxCMS 0.3.5 allows remote attackers to execute arbitrary SQL commands via the gender parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Bloofoxcms | 31/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (8.1) | 10% | 💥 Exploit | Bloofoxcms | 29/12/2008 | 16/6/2026 | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Bill Roberts Bloo | 12/3/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) post_id, (2) post_category_id, (3) post_year_month, and (4) static_page_id parameters; and unspecified other vectors. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Bloofoxcms | 23/1/2008 | 16/6/2026 | Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Bloofoxcms | 23/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Bloofoxcms | 26/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Bloofoxcms | 26/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use | |
| Modificada | Media (4.3) | 7.0% | 💥 Exploit | Bloodshed Software Dev-c++ | 31/1/2007 | 16/6/2026 | Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file. | |
| Modificada | Alta (7.5) | 1.4% | — | Bloo | 21/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phoo.base.php in Bill Roberts Bloo 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the descriptorFileList parameter. NOTE: this issue is disputed by CVE since $descriptorFileList is used in a function definition within phoo.base.php | |
| Modificada | Media (6.8) | 1.4% | — | Bloo | 21/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in extensions/googiespell/googlespell_proxy.php in Bill Roberts Bloo 1.0 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.6) | 2.3% | — | Studio Achtundachtzig Bloomooweb Activex Control | 3/11/2006 | 16/6/2026 | BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path… | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Monolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions NO ONE Lives ForeverMonolith Productions Shogo | 31/12/2004 | 16/6/2026 | Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query. | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. |