Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.21%—Websivu WP Power Stats12/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Igor Buyanov WP Power Stats plugin <= 2.2.3 versions.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (6.1)0.49%—Psychostats1/6/202316/6/2026
A vulnerability classified as problematic has been found in Stars Alliance PsychoStats up to 3.2.2a. This affects an unknown part of the file upload/admin/login.php. The manipulation of the argument ref leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 3.2.2b is able…
ModificadaCrítica (9.8)0.90%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce8/5/202317/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
ModificadaCrítica (9.8)0.64%—Little-apps Little Software Stats16/1/202317/6/2026
A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The manipulation leads to improper access controls. The complexity of an attack is…
ModificadaCrítica (9.8)0.65%—Searx Stats Project Searx Stats15/1/202317/6/2026
A vulnerability, which was classified as critical, has been found in pointhi searx_stats. This issue affects some unknown processing of the file cgi/cron.php. The manipulation leads to sql injection. The patch is named 281bd679a4474ddb222d16c1c380f252839cc18f. It is recommended to apply a patch to fix this issue. The…
ModificadaCrítica (9.8)0.66%—Joomla MOD Einsatz Stats Project Joomla MOD Einsatz Stats8/1/202317/6/2026
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The identifier of the…
ModificadaAlta (8.8)0.63%—Dns-stats Hedgehog25/12/202217/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affected by this issue is the function DSCIOManager::dsc_import_input_from_source of the file src/DSCIOManager.cpp. The manipulation leads to sql injection. The attack may be launched remotely. The…
ModificadaMedia (6.1)0.71%—AwstatsDebian LinuxFedoraproject Fedora4/12/202217/6/2026
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
ModificadaCrítica (9.8)1.1%—Democritus D8s-stats7/11/202217/6/2026
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
ModificadaMedia (4.8)0.68%—Acnam WP Server Health Stats16/9/202217/6/2026
The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (7.8)0.47%—Tats W3MFedoraproject Fedora15/8/202217/6/2026
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
ModificadaCrítica (9.8)1.2%—Analytics Stats Counter Statistics Project Analytics Stats Counter Statistics27/6/202217/6/2026
A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.
ModificadaAlta (8.1)83%💥 ExploitBrandexponents Tatsu25/4/202217/6/2026
The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass extension control implemented in the plugin.…
ModificadaMedia (4.8)0.79%—Jenkins Global-build-stats15/3/202217/6/2026
Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Global Build Stats' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
ModificadaMedia (6.1)0.63%—Github Readme Stats Project Github Readme Stats6/1/202217/6/2026
Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError.
ModificadaMedia (4.3)0.51%—Wp-stats Project Wp-stats1/11/202117/6/2026
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
ModificadaMedia (6.1)0.83%—Coinmarketstats Bitcoin / Altcoin Payment Gateway FOR Woocommerce4/10/202117/6/2026
The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET parameter before outputting back in the All Masking Rules page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.3)2.2%—AwstatsDebian LinuxFedoraproject Fedora12/12/202017/6/2026
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
ModificadaCrítica (9.8)3.8%—AwstatsDebian LinuxFedoraproject Fedora7/12/202017/6/2026
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
ModificadaAlta (7.2)1.7%—Trivetechnology Wp-stats-dashboard20/9/201917/6/2026
The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.
ModificadaCrítica (9.8)1.0%—Pvpgn Stats12/6/201817/6/2026
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
Orbitaley — Vulnerabilidades