Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Zerowdd MyblogAI | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.55% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (6.1) | 0.57% | — | Thinkphp-bjyblog Project Thinkphp-bjyblog | 2/12/2021 | 17/6/2026 | thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseController.class.php. The exit function terminates the script and prints a message to the user that contains $_SERVER['HTTP_HOST']. | |
| Modificada | Media (6.1) | 0.87% | — | Laravel-bjyblog Project Laravel-bjyblog | 10/10/2019 | 17/6/2026 | laravel-bjyblog 6.1.1 has XSS via a crafted URL. | |
| Modificada | Media (5) | 8.2% | — | COM Myblog | 26/4/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 3.1% | — | Wikyblog | 27/2/2010 | 16/6/2026 | Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/. | |
| Modificada | Media (5.8) | 1.8% | — | Wikyblog | 27/2/2010 | 16/6/2026 | Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.php/Comment/Main, (2) index.php/Comment/Main/Home_Wiky, or (3) index.php/Edit/Main. | |
| Modificada | Alta (7.5) | 2.5% | — | Wikyblog | 27/2/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute arbitrary PHP code via a URL in the langFile parameter. | |
| Modificada | Media (4.3) | 2.2% | — | Wikyblog | 27/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php/Special/Main/Templates in WikyBlog 1.7.2 and 1.7.3 rc2 allows remote attackers to inject arbitrary web script or HTML via the which parameter in a copy action. | |
| Modificada | Media (5) | 2.1% | — | Myblog | 19/2/2009 | 16/6/2026 | Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Drupal Everyblog | 14/2/2009 | 16/6/2026 | EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Drupal Everyblog | 14/2/2009 | 16/6/2026 | Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrator via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Drupal Everyblog | 14/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Drupal Everyblog | 14/2/2009 | 16/6/2026 | SQL injection vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | Wikyblog | 9/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to index.php/Edit/Main/Home, (3) to parameter to index.php/Special/Main/WhatLinksHere, (4)… | |
| Modificada | Alta (7.5) | 13% | — | Kafooeyblog | 26/12/2008 | 16/6/2026 | Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. | |
| Modificada | Media (4.3) | 1.0% | — | Wellyblog | 21/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in edit.php in wellyblog allows remote attackers to inject arbitrary web script or HTML via the articleid parameter in an add action. | |
| Modificada | Alta (7.5) | 2.5% | — | Myblog | 30/9/2008 | 16/6/2026 | add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin. | |
| Modificada | Media (5.3) | 1.2% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error… | |
| Modificada | Media (5.1) | 0.41% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899. | |
| Modificada | Media (5.1) | 0.92% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action… | |
| Modificada | Media (4.3) | 1.4% | — | Myblog | 2/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php. | |
| Modificada | Media (6.8) | 0.91% | — | Myblog | 2/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php. |