Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Eggblog | 23/9/2011 | 16/6/2026 | eggBlog 4.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by _lib/fckeditor/editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php and certain other files. | |
| Modificada | Alta (7.5) | 1.8% | — | Eggblog | 2/4/2008 | 16/6/2026 | SQL injection vulnerability in eggBlog before 4.0.1 allows remote attackers to execute arbitrary SQL commands via an unspecified cookie. NOTE: this might overlap CVE-2008-0159. | |
| Modificada | Media (6.8) | 1.9% | — | Eggblog | 9/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie. | |
| Modificada | Media (4.3) | 1.3% | — | Eggblog | 15/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home/rss.php in eggblog before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | |
| Modificada | Media (6.8) | 1.5% | — | Eggblog | 1/6/2007 | 16/6/2026 | Session fixation vulnerability in eggblog 3.1.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |
| Modificada | Media (6.8) | 1.8% | — | Epic Designs Eggblog | 22/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eggblog 3.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) edit parameter to (a) admin/articles.php or (b) admin/comments.php, or the (2) add parameter to admin/users.php. | |
| Modificada | Media (6.4) | 1.8% | — | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. | |
| Modificada | Media (4.3) | 2.0% | — | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php. | |
| Modificada | Media (4.3) | 1.2% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields. | |
| Modificada | Alta (7.8) | 1.6% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability. |