Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2638▼ 297 respecto a la semana anterior
Críticas / altas1351▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
1623 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.32% | — | Adenion Blog2socialAI | 25/9/2026 | 25/9/2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.20% | — | VW Writer BlogAI | 19/9/2026 | 21/9/2026 | The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (6.5) | 0.22% | — | JetblogAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_posts table using only the attacker-supplied b2s_id primary key with no blog_user_id… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to low-privileged accounts. The b2s_search_user AJAX handler in includes/Ajax/Get.php invokes B2S_Tools::searchUser() in includes/Tools.php, which returns the email address of every matching user without… | |
| Aplazada | Media (5.3) | 0.28% | — | Adenion Blog2socialAI | 16/9/2026 | 24/9/2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. The b2s_get_select_mandant_user AJAX handler in includes/Ajax/Get.php resolves arbitrary user IDs supplied in the owner parameter to display names without verifying that the caller is authorized to… | |
| En análisis | Crítica (9.9) | 0.42% | — | Oracle Weblogic ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Weblogic Server | 15/9/2026 | 28/9/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 15/9/2026 | 28/9/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 15/9/2026 | 28/9/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Weblogic Server | 15/9/2026 | 29/9/2026 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic… | |
| Aplazada | Media (5.1) | 0.33% | — | Moxi624 Mogu BlogAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched… | |
| Aplazada | Media (5.1) | 0.35% | — | Quequnlong Shiyi-blogAI | 13/9/2026 | 15/9/2026 | A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be… | |
| Aplazada | Media (5.1) | 0.35% | — | Quequnlong Shiyi-blogAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from… | |
| Aplazada | Media (5.3) | 0.47% | — | Quequnlong Shiyi-blogAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project… | |
| Aplazada | Media (5.3) | 0.37% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions can supply a category uid to retrieve… | |
| Aplazada | Media (5.3) | 0.37% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts including administrators. | |
| Aplazada | Media (6.9) | 0.45% | — | MogublogAI | 11/9/2026 | 15/9/2026 | MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user identifier to suppress reply… | |
| Aplazada | Alta (8.7) | 0.54% | — | MogublogAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from… | |
| Aplazada | Media (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Aplazada | Alta (8.7) | 0.73% | — | MogublogAIDom4jAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions.… | |
| Aplazada | Media (6.9) | 0.41% | — | Appleple A-blog CMSAI | 11/9/2026 | 16/9/2026 | a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product. | |
| Analizada | Alta (7.5) | 0.56% | — | Mageplaza Magefan Blog | 9/9/2026 | 10/9/2026 | Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql. | |
| Analizada | Alta (8.6) | 0.47% | — | Mageplaza Blog | 9/9/2026 | 10/9/2026 | SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view. | |
| Aplazada | Media (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 7/9/2026 | 8/9/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… |