Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.98% | — | Bblog Project Bblog | 8/4/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in bBlog allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Alta (7.5) | 0.97% | — | Wbblog | 3/10/2008 | 16/6/2026 | SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Wbblog | 16/3/2007 | 16/6/2026 | SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_id parameter in a viewentry cmd. | |
| Modificada | Media (4.3) | 1.6% | — | Liqua Wbblog | 16/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script or HTML via the e_id parameter in a viewentry cmd. | |
| Modificada | Media (4.3) | 1.3% | — | Eaden Mckee Bblog | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text. | |
| Modificada | Alta (7.5) | 1.3% | — | Eaden Mckee Bblog | 23/4/2005 | 16/6/2026 | SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Eaden Mckee Bblog | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in bBlog 0.7.2 and 0.7.3 allows remote attackers to execute arbitrary SQL commands via the p parameter. | |
| Modificada | Media (4.8) | 0.96% | — | Bblog | 26/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administration panel in bBlog 0.7.2 allows remote authenticated users with superuser privileges to inject arbitrary web script or HTML via a blog name ($blogname). NOTE: if administrators are normally allowed to add HTML by other means, e.g. through Smarty templates,… |