Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.65% | — | Searx Stats Project Searx Stats | 15/1/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in pointhi searx_stats. This issue affects some unknown processing of the file cgi/cron.php. The manipulation leads to sql injection. The patch is named 281bd679a4474ddb222d16c1c380f252839cc18f. It is recommended to apply a patch to fix this issue. The… | |
| Modificada | Crítica (9.8) | 0.66% | — | Joomla MOD Einsatz Stats Project Joomla MOD Einsatz Stats | 8/1/2023 | 17/6/2026 | A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the… | |
| Modificada | Alta (8.8) | 0.63% | — | Dns-stats Hedgehog | 25/12/2022 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affected by this issue is the function DSCIOManager::dsc_import_input_from_source of the file src/DSCIOManager.cpp. The manipulation leads to sql injection. The attack may be launched remotely. The… | |
| Modificada | Media (6.1) | 0.71% | — | AwstatsDebian LinuxFedoraproject Fedora | 4/12/2022 | 17/6/2026 | AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. | |
| Modificada | Crítica (9.8) | 1.1% | — | Democritus D8s-stats | 7/11/2022 | 17/6/2026 | The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0. | |
| Modificada | Media (4.8) | 0.68% | — | Acnam WP Server Health Stats | 16/9/2022 | 17/6/2026 | The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 1.2% | — | Analytics Stats Counter Statistics Project Analytics Stats Counter Statistics | 27/6/2022 | 17/6/2026 | A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely. | |
| Modificada | Media (4.8) | 0.79% | — | Jenkins Global-build-stats | 15/3/2022 | 17/6/2026 | Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission. | |
| Modificada | Media (6.1) | 0.63% | — | Github Readme Stats Project Github Readme Stats | 6/1/2022 | 17/6/2026 | Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError. | |
| Modificada | Media (4.3) | 0.51% | — | Wp-stats Project Wp-stats | 1/11/2021 | 17/6/2026 | The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads | |
| Modificada | Media (6.1) | 0.83% | — | Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce | 4/10/2021 | 17/6/2026 | The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.3) | 2.2% | — | AwstatsDebian LinuxFedoraproject Fedora | 12/12/2020 | 17/6/2026 | In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600. | |
| Modificada | Crítica (9.8) | 3.8% | — | AwstatsDebian LinuxFedoraproject Fedora | 7/12/2020 | 17/6/2026 | In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501. | |
| Modificada | Alta (7.2) | 1.7% | — | Trivetechnology Wp-stats-dashboard | 20/9/2019 | 17/6/2026 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter. | |
| Modificada | Media (5.3) | 1.9% | 💥 Exploit | Awstats | 20/4/2018 | 17/6/2026 | A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters. | |
| Modificada | Media (6.1) | 0.84% | — | Jenkins Global-build-stats | 26/1/2018 | 17/6/2026 | Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability.… | |
| Modificada | Crítica (9.8) | 4.4% | — | AwstatsDebian Linux | 3/1/2018 | 17/6/2026 | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution. | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Smartertools Smarterstats | 30/9/2017 | 17/6/2026 | SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Robotstats | 8/12/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Robotstats | 8/12/2014 | 17/6/2026 | SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL commands via the robot parameter to admin/robots.php. |