Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.45%—Ttttonyhe OblogAI6/8/202612/8/2026
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed…
AplazadaBaja (1.3)0.39%—Liangliangyy DjangoblogAI20/4/202617/6/2026
A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component File Upload Endpoint. Performing a manipulation of the argument SECRET_KEY results in use of hard-coded cryptographic key . Remote exploitation of the attack is…
AplazadaBaja (2.9)0.42%—Liangliangyy DjangoblogAI20/4/202617/6/2026
A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file djangoblog/settings.py of the component Setting Handler. Such manipulation of the argument USER/PASSWORD leads to hard-coded credentials. The attack may be launched remotely. The attack…
AplazadaBaja (2.1)0.35%—Liangliangyy DjangoblogAI20/4/202617/6/2026
A flaw has been found in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function form_valid of the file oauth/views.py. This manipulation of the argument oauthid causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was…
AplazadaMedia (5.5)0.47%—Liangliangyy DjangoblogAI19/4/202617/6/2026
A security vulnerability has been detected in liangliangyy DjangoBlog up to 2.1.0.0. Affected is an unknown function of the file owntracks/views.py of the component Amap API Call Handler. Such manipulation of the argument key leads to use of hard-coded cryptographic key . The attack may be launched remotely. The…
AplazadaMedia (5.5)0.72%—Liangliangyy DjangoblogAI19/4/202617/6/2026
A weakness has been identified in liangliangyy DjangoBlog up to 2.1.0.0. This impacts an unknown function of the file blog/views.py of the component Clean Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used…
AplazadaBaja (2.9)0.40%—Liangliangyy DjangoblogAI19/4/202617/6/2026
A security flaw has been discovered in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangoblog/settings.py of the component Setting Handler. The manipulation of the argument SECRET_KEY results in hard-coded credentials. The attack can be launched remotely. The attack requires a…
AplazadaMedia (5.5)0.65%—Liangliangyy DjangoblogAI19/4/202617/6/2026
A vulnerability was identified in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of the file owntracks/views.py of the component logtracks Endpoint. The manipulation leads to missing authentication. The attack can be initiated remotely. The exploit is publicly available and might be…
AplazadaBaja (2.1)2.4%—Liangliangyy DjangoblogAI19/4/202617/6/2026
A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanager/api/commonapi.py of the component WeChat Bot Interface. Executing a manipulation of the argument Source can lead to command injection. It is possible to launch the…
AplazadaMedia (4.3)0.12%—WP Admin MicroblogAI18/11/202517/6/2026
The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the 'wp-admin-microblog' page. This makes it possible for unauthenticated attackers to send messages on behalf of an administrator…
AplazadaAlta (7.1)0.13%—Efficientscripts Microblog PosterAI28/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Efficient Scripts Microblog Poster microblog-poster allows Stored XSS.This issue affects Microblog Poster: from n/a through <= 2.1.6.
ModificadaCrítica (9.8)0.81%—Leotheme Leoblog15/9/202317/6/2026
LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.
ModificadaMedia (5.4)0.41%—Djangoblog Project Djangoblog29/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.
ModificadaAlta (7.2)1.9%—Efficientscripts Microblog Poster26/9/201917/6/2026
The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=microblogposter.php account_id parameter.
ModificadaMedia (4.3)1.5%—Social Microblogging PRO Project Social Microblogging PRO5/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site" input in the Profile section.
ModificadaMedia (4.3)1.6%—WP Microblogs Project WP Microblogs2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the oauth_verifier parameter.
ModificadaMedia (5.8)0.96%—Tencent MicroblogpadTencent Wblog25/1/201216/6/2026
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.
ModificadaMedia (5)1.3%—Microblog23/9/201116/6/2026
MicroBlog 0.9.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by init.php and certain other files.
ModificadaMedia (6.8)1.7%—Dootzky Oblog25/6/201016/6/2026
admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.
ModificadaMedia (4.3)1.6%—Dootzky Oblog25/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HTML via the (1) commentName, (2) commentEmail, (3) commentWeb, or (4) commentText parameter to article.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the…
ModificadaMedia (6.8)1.1%—Dootzky Oblog25/6/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in oBlog allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin password, (2) force an admin logout, (3) change the visibility of posts, (4) remove links, and (5) change the name fields of a blog.
ModificadaMedia (5)1.2%—Dootzky Oblog25/6/201016/6/2026
article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new action.
ModificadaMedia (4.3)1.0%—Dootzky Oblog25/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in oBlog allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.5%—Ezpx Photoblog18/6/201016/6/2026
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.
ModificadaAlta (7.5)2.3%—Mojoblog21/4/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php.