Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in ZeroWdd myblog 1.0. Affected is the function update of the file src/main/java/com/wdd/myblog/controller/admin/BlogController.java. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function upload of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.3) | 0.48% | — | Zerowdd MyblogAI | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.55% | — | Zerowdd Myblog | 8/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5) | 8.2% | — | COM Myblog | 26/4/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.1% | — | Myblog | 19/2/2009 | 16/6/2026 | Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 2.5% | — | Myblog | 30/9/2008 | 16/6/2026 | add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin. | |
| Modificada | Media (5.1) | 0.41% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899. | |
| Modificada | Media (5.3) | 1.2% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error… | |
| Modificada | Media (5.1) | 0.92% | — | Mywebland Mybloggie | 9/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action… | |
| Modificada | Media (4.3) | 1.4% | — | Myblog | 2/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php. | |
| Modificada | Media (6.8) | 0.91% | — | Myblog | 2/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mywebland Mybloggie | 12/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE:… | |
| Modificada | Alta (7.5) | 1.0% | — | Mywebland Mybloggie | 4/6/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225. | |
| Modificada | Media (6.5) | 1.2% | — | Myblog | 18/4/2007 | 16/6/2026 | Direct static code injection vulnerability in admin/settings.php in MyBlog 0.9.8 and earlier allows remote authenticated admin users to inject arbitrary PHP code via the content parameter, which can be executed by accessing index.php. NOTE: a separate vulnerability could be leveraged to make this issue exploitable by… | |
| Modificada | Alta (7.5) | 6.6% | — | Myblog | 18/4/2007 | 16/6/2026 | MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php. | |
| Modificada | Alta (7.5) | 1.2% | — | SAM Crew Myblog | 12/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (6.8) | 3.3% | — | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter. | |
| Modificada | Media (4.3) | 0.89% | — | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 2.7% | — | Mywebland Mybloggie | 19/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.php and (2) login.php in myBloggie 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO string. | |
| Modificada | Alta (7.5) | 1.9% | — | Mywebland Mybloggie | 9/8/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters. | |
| Modificada | Media (5) | 1.7% | — | Mywebland Mybloggie | 9/8/2006 | 16/6/2026 | index.php in myWebland myBloggie 2.1.4 and earlier allows remote attackers to obtain sensitive information via a query that only specifies the viewdate mode, which reveals the table prefix in a SQL error message. | |
| Modificada | Media (5.8) | 2.1% | — | Mywebland Mybloggie | 27/7/2006 | 16/6/2026 | CRLF injection vulnerability in (1) index.php and (2) admin.php in myWebland MyBloggie 2.1.3 allows remote attackers to hijack sessions and conduct cross-site scripting (XSS) attacks via a cookie. | |
| Modificada | Alta (7.5) | 1.5% | — | Mywebland Mybloggie | 27/7/2006 | 16/6/2026 | SQL injection vulnerability in Webland MyBloggie 2.1.3 allows remote attackers to execute arbitrary SQL commands via the (1) post_id parameter in index.php and (2) search function. | |
| Modificada | Alta (7.5) | 1.8% | — | Mywebland Mybloggie | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in MyBloggie 2.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mybloggie_root_path parameter to (1) admin.php or (2) scode.php. NOTE: this issue has been disputed in multiple third party followups, which say that the MyBloggie source code… |