Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2517▼ 423 respecto a la semana anterior
Críticas / altas1296▲ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)57▼ 471 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Javaweb Blog Project Javaweb Blog26/1/202317/6/2026
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
ModificadaMedia (5.4)0.39%—Javaweb Blog Project Javaweb Blog23/1/202317/6/2026
Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.
ModificadaMedia (6.8)1.1%—Comdev WEB Blogger23/2/200916/6/2026
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
ModificadaAlta (7.5)1.3%—Comdev WEB Blogger6/6/200716/6/2026
PHP remote file inclusion vulnerability in sampleblogger.php in Comdev Web Blogger 4.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter, a different vector than CVE-2006-5441.
ModificadaAlta (7.5)1.5%—Comdev WEB Blogger20/10/200616/6/2026
PHP remote file inclusion vulnerability in adminfoot.php in Comdev Web Blogger 4.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party…
ModificadaMedia (6.5)1.3%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pathname.
ModificadaMedia (5)1.4%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password.
ModificadaMedia (4.3)1.2%—Leif M. Wright WEB Blog22/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, which are stored in a log file and not sanitized when the administrator views the "Log" page, possibly using the…
ModificadaAlta (7.5)1.7%—Leif M. Wright WEB Blog22/2/200616/6/2026
Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.
ModificadaAlta (7.5)9.9%—Leif M. Wright WEB Blog31/12/200416/6/2026
blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.
ModificadaMedia (5)3.6%—Leif M. Wright WEB Blog20/1/200416/6/2026
Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable.