Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.60%—OneblogAI7/7/20269/7/2026
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component
ModificadaCrítica (9.8)0.49%—Zhyd Oneblog28/10/202517/6/2026
zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
AnalizadaAlta (7.5)0.40%—Zhyd Oneblog16/9/202517/6/2026
The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.
AnalizadaMedia (5.3)0.34%—Zhyd Oneblog27/3/202517/6/2026
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.71%—Zhyd Oneblog27/3/202517/6/2026
A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The…
AnalizadaAlta (8)0.45%—Zhyd Oneblog10/2/202517/6/2026
OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
AplazadaMedia (6.5)0.26%—Wpcone ConeblogAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCone ConeBlog – WordPress Blog Widgets coneblog-widgets.This issue affects ConeBlog – WordPress Blog Widgets: from n/a through <= 1.4.8.
AnalizadaMedia (5.4)0.40%—Zhyd Oneblog20/3/202417/6/2026
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module.
AnalizadaMedia (6.1)0.37%—Zhyd Oneblog20/3/202417/6/2026
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module.
ModificadaMedia (5.4)0.38%—Zhyd Oneblog20/3/202417/6/2026
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module.
ModificadaMedia (5.4)0.39%—Zhyd Oneblog20/3/202417/6/2026
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module.
AnalizadaMedia (6.1)0.38%—Zhyd Oneblog20/3/202417/6/2026
OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links.
AnalizadaMedia (6.1)0.38%—Zhyd Oneblog20/3/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module.
ModificadaMedia (4.3)0.57%—Zhyd Oneblog23/6/202217/6/2026
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
ModificadaMedia (6.5)0.58%—Zhyd Oneblog23/6/202217/6/2026
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
ModificadaMedia (4.3)0.57%—Zhyd Oneblog23/6/202217/6/2026
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
ModificadaMedia (6.5)0.67%—Oneblog Project Oneblog25/1/202217/6/2026
OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority.
ModificadaMedia (5.4)0.50%—Oneblog Project Oneblog19/1/202217/6/2026
A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background.