Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.36%—Mtons Mblog26/8/202517/6/2026
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and…
AnalizadaBaja (2.1)0.36%—Mtons Mblog26/8/202517/6/2026
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
AnalizadaBaja (1.9)0.27%—Mtons Mblog26/8/202517/6/2026
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
AnalizadaBaja (2)0.26%—Mtons Mblog26/8/202517/6/2026
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaAlta (7.5)0.36%—Perfreeblog25/8/202517/6/2026
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
AnalizadaAlta (7.5)0.91%—Perfreeblog25/8/202517/6/2026
PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.
AnalizadaBaja (2)0.25%—Mtons Mblog25/8/202517/6/2026
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other…
AplazadaBaja (2.1)0.27%—Tencent WblogAI24/8/202517/6/2026
A vulnerability was identified in wangsongyan wblog 0.0.1. This affects the function RestorePost of the file backup.go. Such manipulation of the argument fileName leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was…
AplazadaAlta (7.5)0.36%—SpringbootblogAI22/8/202517/6/2026
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication.
AplazadaCrítica (9.8)0.51%—Zhisheng17 BlogAI22/8/202517/6/2026
zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.
AnalizadaMedia (6.9)0.29%—Dogukanurker Flaskblog19/8/202517/6/2026
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when deleting a comment, there's no validation of the ownership of the comment. Every user can delete an arbitrary comment of another user on every post, by simply intercepting the delete request and changing the commentID. The code that causes the…
AnalizadaCrítica (9.3)0.27%—Dogukanurker Flaskblog19/8/202517/6/2026
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, an arbitrary user can change his role to "admin", giving its relative privileges (e.g. delete users, posts, comments etc.). The problem is in the routes/adminPanelUsers file.
AnalizadaMedia (5.3)0.21%—Dogukanurker Flaskblog19/8/202517/6/2026
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, when creating a post, there's no validation of the content of the post stored in the variable "postContent". The vulnerability arises when displaying the content of the post using the | safe filter, that tells the engine to not escape the rendered…
AnalizadaMedia (6.9)0.37%—Dogukanurker Flaskblog19/8/202517/6/2026
flaskBlog is a blog app built with Flask. In 2.8.0 and earlier, the code checks if the userRole is "admin" only when visiting the /admin page, but not when visiting its subroutes. Specifically, only the file routes/adminPanel.py checks the user role when a user is trying to access the admin page, but that control is…
AplazadaBaja (2.1)0.29%—Liuyuyang01 Thrivex-blogAI19/8/202517/6/2026
A security flaw has been discovered in LiuYuYang01 ThriveX-Blog up to 3.1.7. Affected by this vulnerability is the function updateJsonValueByName of the file /web_config/json/name/web. Performing manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (2)0.25%—Zhenfeng13 My-blog18/8/202517/6/2026
A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.55%—Zhenfeng13 My-blog18/8/202517/6/2026
A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be initiated remotely. The exploit has been…
AnalizadaBaja (2.9)0.59%—Mtons Mblog15/8/202517/6/2026
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.…
AnalizadaBaja (2.9)0.87%—Mtons Mblog15/8/202517/6/2026
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is…
AnalizadaBaja (2.1)0.27%—Mtons Mblog15/8/202517/6/2026
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AplazadaMedia (6.5)0.17%—Michael Nelson Print MY BlogAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Print My Blog print-my-blog allows Stored XSS.This issue affects Print My Blog: from n/a through <= 3.27.9.
AnalizadaMedia (5.3)0.22%—Dogukanurker Flaskblog14/8/202517/6/2026
flaskBlog is a blog app built with Flask. In versions 2.8.1 and prior, improper sanitization of postContent when submitting POST requests to /createpost leads to arbitrary JavaScript execution (XSS) on all pages the post is reflected on including /, /post/[ID], /admin/posts, and /user/[ID] of the user that made the…
AplazadaMedia (6.5)0.21%—Sparklewpthemes Blogger BuzzAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Blogger Buzz blogger-buzz allows Stored XSS.This issue affects Blogger Buzz: from n/a through <= 1.2.6.
AplazadaAlta (7.1)0.23%—Johnh10 Video Blogster LiteAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Reflected XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2.
AnalizadaBaja (2.9)0.62%—Mtons Mblog13/8/202517/6/2026
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive authentication attempts. The attack may be launched…