Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 9.7% | — | Wp-statistics WP StatisticsAI | 27/9/2025 | 17/6/2026 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.13% | — | Jeff Starr Simple Statistics FOR FeedsAI | 22/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeff Starr Simple Statistics for Feeds simple-feed-stats allows Cross Site Request Forgery.This issue affects Simple Statistics for Feeds: from n/a through <= 20250322. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. | |
| Aplazada | Media (4.3) | 0.20% | — | Veronalabs WP StatisticsAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15. | |
| Modificada | Media (5.3) | 0.33% | — | Jenkins Statistics Gatherer | 9/7/2025 | 17/6/2026 | Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (6.5) | 0.38% | — | Jenkins Statistics Gatherer | 9/7/2025 | 17/6/2026 | Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system. | |
| Aplazada | Media (6.5) | 0.19% | — | Osama.esh WP Visitor StatisticsAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Stored XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.8. | |
| Aplazada | Media (4.3) | 0.15% | — | Burst-statistics Burst StatisticsAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Burst Statistics B.V. Burst Statistics burst-statistics allows Cross Site Request Forgery.This issue affects Burst Statistics: from n/a through <= 2.0.6. | |
| Aplazada | Media (5.3) | 0.40% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.4. | |
| Aplazada | Media (4.3) | 0.17% | — | Chris Clark Lessbuttons Social Sharing AND StatisticsAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics lessbuttons allows Cross Site Request Forgery.This issue affects LessButtons Social Sharing and Statistics: from n/a through <= 1.6.1. | |
| Aplazada | Media (5.4) | 0.27% | — | Wp-statistics WP StatisticsAI | 30/4/2025 | 17/6/2026 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.4) | 0.67% | — | Tibco Spotfire Enterprise Runtime FOR RTibco Spotfire Statistics ServicesTibco Spotfire AnalystTibco Spotfire Deployment KIT+2 | 9/4/2025 | 17/6/2026 | Injection Vulnerabilities: Attackers can inject malicious code, potentially gaining control over the system executing these functions. Additionally, insufficient validation of filenames during file uploads can enable attackers to upload and execute malicious files, leading to arbitrary code execution | |
| Aplazada | Media (4.3) | 0.37% | — | Greg Ross Just Writing StatisticsAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Greg Ross Just Writing Statistics just-writing-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Just Writing Statistics: from n/a through <= 5.3. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM Spss Statistics | 25/3/2025 | 17/6/2026 | IBM SPSS Statistics 26.0, 27.0.1, 28.0.1, and 29.0.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | |
| Aplazada | Media (6.5) | 0.35% | — | Osama.esh WP Visitor Statistics Real Time TrafficAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Stored XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.2. | |
| Aplazada | Media (4.3) | 0.32% | — | Osama.esh WP Visitor StatisticsAI | 7/1/2025 | 17/6/2026 | Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.5. | |
| Aplazada | Alta (7.6) | 0.43% | — | Greg Ross Just Writing StatisticsAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Greg Ross Just Writing Statistics just-writing-statistics allows SQL Injection.This issue affects Just Writing Statistics: from n/a through <= 4.7. | |
| Aplazada | Media (4.3) | 0.36% | — | Wp-buy Visitors-traffic-real-time-statisticsAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in wp-buy Visitors Traffic Real Time Statistics visitors-traffic-real-time-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visitors Traffic Real Time Statistics: from n/a through <= 7.2. | |
| Aplazada | Media (6.8) | 0.38% | — | Spotfire Enterprise Runtime FOR R - Server EditionAISpotfire Statistics ServicesAISpotfire DesktopAISpotfireAI+1 | 27/6/2024 | 17/6/2026 | Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows The impact of this vulnerability depends on the privileges of the user running the affected software..This issue… | |
| Aplazada | Media (5.9) | 0.26% | — | Greggross Just Writing StatisticsAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GregRoss Just Writing Statistics allows Stored XSS.This issue affects Just Writing Statistics: from n/a through 4.5. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Advancedplugins Reports StatisticsAI | 19/3/2024 | 17/6/2026 | An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module. | |
| Modificada | Alta (7.5) | 0.45% | — | Codepress Visitor Statistics | 17/3/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 6.9.4. | |
| Aplazada | Alta (7.2) | 68% | — | Wp-statistics WP StatisticsAI | 13/3/2024 | 17/6/2026 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Media (5.4) | 0.51% | — | Burst-statistics Burst Statistics | 13/3/2024 | 17/6/2026 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Modificada | Media (5.5) | 0.16% | — | IBM Spss Statistics | 8/3/2024 | 17/6/2026 | IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity and cause a denial of service. |