Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.36%—Mtons Mblog29/8/202517/6/2026
A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
AnalizadaBaja (2.1)0.41%—Mtons Mblog26/8/202517/6/2026
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be…
AnalizadaBaja (2.1)0.36%—Mtons Mblog26/8/202517/6/2026
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and…
AnalizadaBaja (2.1)0.36%—Mtons Mblog26/8/202517/6/2026
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
AnalizadaBaja (1.9)0.27%—Mtons Mblog26/8/202517/6/2026
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
AnalizadaBaja (2)0.26%—Mtons Mblog26/8/202517/6/2026
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (2)0.25%—Mtons Mblog25/8/202517/6/2026
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other…
AnalizadaBaja (2.9)0.59%—Mtons Mblog15/8/202517/6/2026
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.…
AnalizadaBaja (2.9)0.87%—Mtons Mblog15/8/202517/6/2026
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is…
AnalizadaBaja (2.1)0.27%—Mtons Mblog15/8/202517/6/2026
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.9)0.62%—Mtons Mblog13/8/202517/6/2026
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive authentication attempts. The attack may be launched…
AplazadaMedia (6.5)0.38%—Jeffikus Woo-tumblogAI3/4/202517/6/2026
Missing Authorization vulnerability in jeffikus WooTumblog woo-tumblog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooTumblog: from n/a through <= 2.1.4.
AnalizadaMedia (5.3)0.46%—Mtons Mblog9/1/202517/6/2026
A vulnerability classified as problematic was found in langhsu Mblog Blog System 3.5.0. Affected by this vulnerability is an unknown functionality of the file /search of the component Search Bar. The manipulation of the argument kw leads to cross site scripting. The attack can be launched remotely. The exploit has…
AnalizadaMedia (6.3)0.68%—Mtons Mblog9/1/202517/6/2026
A vulnerability classified as problematic has been found in langhsu Mblog Blog System 3.5.0. Affected is an unknown function of the file /login. The manipulation leads to observable response discrepancy. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is…
ModificadaCrítica (9.8)1.3%—Mtons Mblog28/3/20249/7/2026
An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.
ModificadaAlta (7.8)0.97%—Mblog Project Mblog8/5/202317/6/2026
OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected.
ModificadaMedia (4.3)0.36%—Mblog Project Mblog20/1/202217/6/2026
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
ModificadaMedia (5.4)0.64%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
ModificadaMedia (5.4)0.64%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
ModificadaMedia (5.4)0.60%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
ModificadaMedia (5.4)0.60%—Mblog Project Mblog1/4/202117/6/2026
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
ModificadaAlta (7.5)1.0%—Robitbt COM Amblog9/10/201116/6/2026
Multiple SQL injection vulnerabilities in the Amblog (com_amblog) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) articleid or (2) catid parameter to index.php.
ModificadaAlta (7.5)0.91%—Mblogger Project Mblogger7/10/201116/6/2026
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands via the postID parameter.
ModificadaAlta (7.5)0.97%—Cfmsource Cfmblog27/2/200916/6/2026
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands via the categorynbr parameter.
ModificadaMedia (6.4)2.4%—C97net Mblog28/12/200716/6/2026
Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter in a page mode action.