Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.60% | — | OneblogAI | 7/7/2026 | 9/7/2026 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component | |
| Modificada | Crítica (9.8) | 0.49% | — | Zhyd Oneblog | 28/10/2025 | 17/6/2026 | zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | |
| Analizada | Alta (7.5) | 0.40% | — | Zhyd Oneblog | 16/9/2025 | 17/6/2026 | The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability. | |
| Analizada | Media (5.3) | 0.34% | — | Zhyd Oneblog | 27/3/2025 | 17/6/2026 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been declared as problematic. Affected by this vulnerability is the function autoLink of the file com/zyd/blog/controller/RestApiController.java. The manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.71% | — | Zhyd Oneblog | 27/3/2025 | 17/6/2026 | A vulnerability was found in zhangyd-c OneBlog up to 2.3.9. It has been classified as problematic. Affected is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (8) | 0.45% | — | Zhyd Oneblog | 10/2/2025 | 17/6/2026 | OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpcone ConeblogAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCone ConeBlog – WordPress Blog Widgets coneblog-widgets.This issue affects ConeBlog – WordPress Blog Widgets: from n/a through <= 1.4.8. | |
| Analizada | Media (5.4) | 0.40% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the User Management module. | |
| Analizada | Media (6.1) | 0.37% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Role Management module. | |
| Modificada | Media (5.4) | 0.38% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Privilege Management module. | |
| Modificada | Media (5.4) | 0.39% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notice Manage module. | |
| Analizada | Media (6.1) | 0.38% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component {{rootpath}}/links. | |
| Analizada | Media (6.1) | 0.38% | — | Zhyd Oneblog | 20/3/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in OneBlog v2.3.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category List parameter under the Lab module. | |
| Modificada | Media (4.3) | 0.57% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module. | |
| Modificada | Media (6.5) | 0.58% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges. | |
| Modificada | Media (4.3) | 0.57% | — | Zhyd Oneblog | 23/6/2022 | 17/6/2026 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls. | |
| Modificada | Media (6.5) | 0.67% | — | Oneblog Project Oneblog | 25/1/2022 | 17/6/2026 | OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators beyond their authority. | |
| Modificada | Media (5.4) | 0.50% | — | Oneblog Project Oneblog | 19/1/2022 | 17/6/2026 | A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in the background. |