Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.45% | — | Ttttonyhe OblogAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Baja (1.3) | 0.39% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Aplazada | Baja (2.9) | 0.42% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remotely. The attack… | |
| Aplazada | Baja (2.1) | 0.35% | — | Liangliangyy DjangoblogAI | 20/4/2026 | 17/6/2026 | A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.47% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.72% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used… | |
| Aplazada | Baja (2.9) | 0.40% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The attack requires a… | |
| Aplazada | Media (5.5) | 0.65% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 2.4% | — | Liangliangyy DjangoblogAI | 19/4/2026 | 17/6/2026 | A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injection. It is possible to launch the… | |
| Aplazada | Media (4.3) | 0.12% | — | WP Admin MicroblogAI | 18/11/2025 | 17/6/2026 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf of an administrator… | |
| Aplazada | Alta (7.1) | 0.13% | — | Efficientscripts Microblog PosterAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Efficient Scripts Microblog Poster microblog-poster allows Stored XSS.This issue affects Microblog Poster: from n/a through <= 2.1.6. | |
| Modificada | Crítica (9.8) | 0.81% | — | Leotheme Leoblog | 15/9/2023 | 17/6/2026 | LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs. | |
| Modificada | Media (5.4) | 0.41% | — | Djangoblog Project Djangoblog | 29/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master. | |
| Modificada | Alta (7.2) | 1.9% | — | Efficientscripts Microblog Poster | 26/9/2019 | 17/6/2026 | The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Social Microblogging PRO Project Social Microblogging PRO | 5/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section. | |
| Modificada | Media (4.3) | 1.6% | — | WP Microblogs Project WP Microblogs | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the oauth_verifier parameter. | |
| Modificada | Media (5.8) | 0.96% | — | Tencent MicroblogpadTencent Wblog | 25/1/2012 | 16/6/2026 | The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application. | |
| Modificada | Media (5) | 1.3% | — | Microblog | 23/9/2011 | 16/6/2026 | MicroBlog 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by init.php and certain other files. | |
| Modificada | Media (6.8) | 1.7% | — | Dootzky Oblog | 25/6/2010 | 16/6/2026 | admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests. | |
| Modificada | Media (4.3) | 1.6% | — | Dootzky Oblog | 25/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the… | |
| Modificada | Media (6.8) | 1.1% | — | Dootzky Oblog | 25/6/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog. | |
| Modificada | Media (5) | 1.2% | — | Dootzky Oblog | 25/6/2010 | 16/6/2026 | article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action. | |
| Modificada | Media (4.3) | 1.0% | — | Dootzky Oblog | 25/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in oBlog allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.5% | — | Ezpx Photoblog | 18/6/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Mojoblog | 21/4/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php. |