Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)38%💥 ExploitCodepress Visitor Statistics21/12/202117/6/2026
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
ModificadaMedia (5.5)0.22%—IBM Spss Statistics17/11/202117/6/2026
IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046.
ModificadaAlta (8.8)1.4%—Wp-buy Visitor Traffic Real Time Statistics8/11/202117/6/2026
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue
ModificadaAlta (7.8)0.25%—Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services29/6/202117/6/2026
The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire…
ModificadaAlta (7.8)0.22%—Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services29/6/202117/6/2026
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO…
ModificadaAlta (7.5)30%💥 ExploitVeronalabs WP Statistics7/6/202117/6/2026
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.
ModificadaAlta (8.8)1.3%—Wp-buy Visitor Traffic Real Time Statistics14/5/202117/6/2026
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers…
ModificadaMedia (4.3)0.80%—Jenkins Cloud Statistics30/3/202117/6/2026
Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages.
ModificadaMedia (6.5)0.53%—View Frontend Statistics Project View Frontend Statistics18/11/202017/6/2026
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be…
ModificadaBaja (3.3)0.35%—Jenkins Couchdb-statistics8/10/202017/6/2026
Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaAlta (8.8)0.80%—Wp-buy Visitor Traffic Real Time Statistics30/8/201917/6/2026
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
ModificadaAlta (8.8)0.74%—Wp-buy Visitor Traffic Real Time Statistics30/8/201917/6/2026
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
ModificadaCrítica (9.8)1.6%—Cesnet Proxystatistics23/8/201917/6/2026
The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
ModificadaCrítica (9.8)2.5%—Veronalabs WP Statistics14/8/201917/6/2026
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
ModificadaCrítica (9.8)2.6%—Veronalabs WP Statistics4/7/201917/6/2026
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
ModificadaMedia (5.4)1.1%—Veronalabs WP Statistics3/6/201917/6/2026
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
ModificadaAlta (8.8)1.5%—Tibco Spotfire Statistics Services14/5/201917/6/2026
The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database,…
ModificadaMedia (6.1)1.4%—Veronalabs WP Statistics23/4/201917/6/2026
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
ModificadaCrítica (9.8)4.0%—Tibco Spotfire Statistics Services10/10/201817/6/2026
The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component.…
ModificadaMedia (6.1)1.2%—Feed Statistics Project Feed Statistics16/9/201817/6/2026
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
ModificadaMedia (6.1)0.71%—Veronalabs WP Statistics26/6/201817/6/2026
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL…
ModificadaMedia (6.1)2.4%💥 ExploitChanguondyu Advanced Statistics Project Changuondyu Advanced Statistics29/5/201817/6/2026
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.
ModificadaMedia (6.1)0.76%—Wp-statistics WP Statistics7/7/201717/6/2026
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
ModificadaMedia (6.1)1.3%—Wp-statistics WP Statistics28/4/201717/6/2026
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.1)2.6%—WP Statistics28/4/201717/6/2026
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Orbitaley — Vulnerabilidades