Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 38% | 💥 Exploit | Codepress Visitor Statistics | 21/12/2021 | 17/6/2026 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks | |
| Modificada | Media (5.5) | 0.22% | — | IBM Spss Statistics | 17/11/2021 | 17/6/2026 | IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of service by writing arbitrary files to admin protected directories on the system. IBM X-Force ID: 212046. | |
| Modificada | Alta (8.8) | 1.4% | — | Wp-buy Visitor Traffic Real Time Statistics | 8/11/2021 | 17/6/2026 | The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue | |
| Modificada | Alta (7.8) | 0.25% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services | 29/6/2021 | 17/6/2026 | The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire… | |
| Modificada | Alta (7.8) | 0.22% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services | 29/6/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO… | |
| Modificada | Alta (7.5) | 30% | 💥 Exploit | Veronalabs WP Statistics | 7/6/2021 | 17/6/2026 | The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones. | |
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy Visitor Traffic Real Time Statistics | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers… | |
| Modificada | Media (4.3) | 0.80% | — | Jenkins Cloud Statistics | 30/3/2021 | 17/6/2026 | Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission and knowledge of random activity IDs to view related provisioning exception error messages. | |
| Modificada | Media (6.5) | 0.53% | — | View Frontend Statistics Project View Frontend Statistics | 18/11/2020 | 17/6/2026 | An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext passwords if ext:felogin is installed) may be… | |
| Modificada | Baja (3.3) | 0.35% | — | Jenkins Couchdb-statistics | 8/10/2020 | 17/6/2026 | Jenkins couchdb-statistics Plugin 0.3 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 0.80% | — | Wp-buy Visitor Traffic Real Time Statistics | 30/8/2019 | 17/6/2026 | The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. | |
| Modificada | Alta (8.8) | 0.74% | — | Wp-buy Visitor Traffic Real Time Statistics | 30/8/2019 | 17/6/2026 | The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cesnet Proxystatistics | 23/8/2019 | 17/6/2026 | The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Veronalabs WP Statistics | 14/8/2019 | 17/6/2026 | The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. | |
| Modificada | Crítica (9.8) | 2.6% | — | Veronalabs WP Statistics | 4/7/2019 | 17/6/2026 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection. | |
| Modificada | Media (5.4) | 1.1% | — | Veronalabs WP Statistics | 3/6/2019 | 17/6/2026 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user. | |
| Modificada | Alta (8.8) | 1.5% | — | Tibco Spotfire Statistics Services | 14/5/2019 | 17/6/2026 | The web interface component of TIBCO Software Inc.'s TIBCO Spotfire Statistics Services contains a vulnerability that might theoretically allow an authenticated user to access sensitive information needed by the Spotfire Statistics Services server. The sensitive information that might be affected includes database,… | |
| Modificada | Media (6.1) | 1.4% | — | Veronalabs WP Statistics | 23/4/2019 | 17/6/2026 | The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request. | |
| Modificada | Crítica (9.8) | 4.0% | — | Tibco Spotfire Statistics Services | 10/10/2018 | 17/6/2026 | The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permissions of the system account used to run the web server component.… | |
| Modificada | Media (6.1) | 1.2% | — | Feed Statistics Project Feed Statistics | 16/9/2018 | 17/6/2026 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. | |
| Modificada | Media (6.1) | 0.71% | — | Veronalabs WP Statistics | 26/6/2018 | 17/6/2026 | WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL… | |
| Modificada | Media (6.1) | 2.4% | 💥 Exploit | Changuondyu Advanced Statistics Project Changuondyu Advanced Statistics | 29/5/2018 | 17/6/2026 | An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field. | |
| Modificada | Media (6.1) | 0.76% | — | Wp-statistics WP Statistics | 7/7/2017 | 17/6/2026 | The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page. | |
| Modificada | Media (6.1) | 1.3% | — | Wp-statistics WP Statistics | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.1) | 2.6% | — | WP Statistics | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. |