Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.65%—Searx Stats Project Searx Stats15/1/202317/6/2026
A vulnerability, which was classified as critical, has been found in pointhi searx_stats. This issue affects some unknown processing of the file cgi/cron.php. The manipulation leads to sql injection. The patch is named 281bd679a4474ddb222d16c1c380f252839cc18f. It is recommended to apply a patch to fix this issue. The…
ModificadaCrítica (9.8)0.66%—Joomla MOD Einsatz Stats Project Joomla MOD Einsatz Stats8/1/202317/6/2026
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the…
ModificadaAlta (8.8)0.63%—Dns-stats Hedgehog25/12/202217/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affected by this issue is the function DSCIOManager::dsc_import_input_from_source of the file src/DSCIOManager.cpp. The manipulation leads to sql injection. The attack may be launched remotely. The…
ModificadaMedia (6.1)0.71%—AwstatsDebian LinuxFedoraproject Fedora4/12/202217/6/2026
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
ModificadaCrítica (9.8)1.1%—Democritus D8s-stats7/11/202217/6/2026
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
ModificadaMedia (4.8)0.68%—Acnam WP Server Health Stats16/9/202217/6/2026
The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaCrítica (9.8)1.2%—Analytics Stats Counter Statistics Project Analytics Stats Counter Statistics27/6/202217/6/2026
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.
ModificadaMedia (4.8)0.79%—Jenkins Global-build-stats15/3/202217/6/2026
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
ModificadaMedia (6.1)0.63%—Github Readme Stats Project Github Readme Stats6/1/202217/6/2026
Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.
ModificadaMedia (4.3)0.51%—Wp-stats Project Wp-stats1/11/202117/6/2026
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
ModificadaMedia (6.1)0.83%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce4/10/202117/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.3)2.2%—AwstatsDebian LinuxFedoraproject Fedora12/12/202017/6/2026
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
ModificadaCrítica (9.8)3.8%—AwstatsDebian LinuxFedoraproject Fedora7/12/202017/6/2026
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
ModificadaAlta (7.2)1.7%—Trivetechnology Wp-stats-dashboard20/9/201917/6/2026
The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.
ModificadaMedia (5.3)1.9%💥 ExploitAwstats20/4/201817/6/2026
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters.
ModificadaMedia (6.1)0.84%—Jenkins Global-build-stats26/1/201817/6/2026
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability.…
ModificadaCrítica (9.8)4.4%—AwstatsDebian Linux3/1/201817/6/2026
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
ModificadaMedia (6.1)2.5%💥 ExploitSmartertools Smarterstats30/9/201717/6/2026
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.
ModificadaMedia (4.3)3.2%💥 ExploitRobotstats8/12/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.
ModificadaAlta (7.5)2.3%💥 ExploitRobotstats8/12/201417/6/2026
SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL commands via the robot parameter to admin/robots.php.
Orbitaley — Vulnerabilidades