Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.11% | — | Fantomas42 Django-blog-zinniaAI | 19/7/2026 | 20/7/2026 | A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in cleartext storage of sensitive information. The… | |
| Aplazada | Baja (1.9) | 0.35% | — | Bolo BlogAI | 24/3/2026 | 17/6/2026 | A security flaw has been discovered in bolo-blog up to 2.6.4. The affected element is an unknown function of the file /console/article/ of the component Article Title Handler. Performing a manipulation of the argument articleTitle results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.5) | 0.30% | — | Twitter Posts TO BlogAI | 11/2/2026 | 17/6/2026 | The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dg_tw_options' function in all versions up to, and including, 1.11.25. This makes it possible for unauthenticated attackers to update plugin settings including Twitter API… | |
| Aplazada | Alta (7.1) | 0.13% | — | Johnh10 Video Blogster LiteAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. | |
| Aplazada | Alta (7.5) | 0.36% | — | SpringbootblogAI | 22/8/2025 | 17/6/2026 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication. | |
| Aplazada | Alta (7.1) | 0.23% | — | Johnh10 Video Blogster LiteAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Reflected XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. | |
| Analizada | Media (6.1) | 0.26% | — | Suhas93 SEO Blogger TO Wordpress 301 Redirector | 23/1/2025 | 17/6/2026 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (7.5) | 0.65% | — | Mandelo SSM Shiro Blog | 10/1/2024 | 17/6/2026 | A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles of the component Backend. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.8) | 0.36% | — | Berkaygediz O Blog | 21/8/2023 | 9/7/2026 | SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component. | |
| Modificada | Media (6.1) | 0.38% | — | Everestthemes Mocho Blog | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Mocho Blog theme <= 1.0.4 versions. | |
| Modificada | Crítica (9.8) | 2.6% | — | Nttr GOO Blog | 29/3/2022 | 17/6/2026 | NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request. | |
| Modificada | Media (5.3) | 0.99% | — | Nttr GOO Blog | 9/6/2021 | 17/6/2026 | Improper access control vulnerability in goo blog App for Android ver.1.2.25 and earlier and for iOS ver.1.3.3 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App. | |
| Modificada | Crítica (9.8) | 1.5% | — | Bo-blog BW | 7/2/2019 | 17/6/2026 | Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this parameter is mishandled in the mode/admin.mode.php delBlockedBatch function. | |
| Modificada | Media (5.4) | 0.27% | — | Masquito2013 Masquito Blogger | 21/10/2014 | 17/6/2026 | The Masquito Blogger (aka com.wmasquito) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Pangramsoft Pointter PHP Micro-blogging Social Network | 22/12/2010 | 16/6/2026 | Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Revou Micro Blogging Twitter Clone | 25/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Jooblog | 13/11/2008 | 16/6/2026 | SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the PostID parameter to index.php. | |
| Modificada | Media (4.3) | 0.84% | — | Domino Blogsphere | 11/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Domino Blogsphere 3.01 Beta 7 allows remote attackers to inject arbitrary web script or HTML via the name field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 13% | 💥 Exploit | Webspotblogging | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php. NOTE: some of these vectors were also reported for 3.0 in… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Webspotblogging | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php. |