Vulnerabilities
Summary — last 7 days
New vulnerabilities2,702▼ 361 vs. last week
Critical / high1,278▼ 199 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)216▼ 113 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (7.6) | 0.42% | — | Appleple A-blogcms | 4/17/2025 | 6/17/2026 | An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path. | |
| Modified | High (8.8) | 0.51% | — | Pramod Blogcms | 6/24/2020 | 6/17/2026 | pramodmahato BlogCMS through 2019-12-31 has admin/changepass.php CSRF. | |
| Modified | Medium (6.1) | 0.66% | — | Blogcms Project Blogcms | 9/10/2018 | 6/17/2026 | BlogCMS through 2016-10-25 has XSS via a comment. | |
| Modified | Medium (6.8) | 1.0% | 💥 Exploit | Blogcms Blog\ | 3/1/2011 | 6/16/2026 | Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allows remote attackers to hijack the authentication of administrators. | |
| Modified | Medium (4.3) | 2.0% | 💥 Exploit | Blogcms Blog\ | 3/1/2011 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) body parameter to action.php and the (2) amount and (3) action parameters to admin/index.php. | |
| Modified | Medium (4.3) | 2.2% | 💥 Exploit | Txtblogcms Txtblog | 12/17/2008 | 6/16/2026 | Directory traversal vulnerability in index.php in TxtBlog 1.0 Alpha allows remote attackers to read arbitrary files via a .. (dot dot) in the m parameter. |