Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter. | |
| Modificada | Crítica (9.8) | 1.0% | — | Pvpgn Stats | 12/6/2018 | 17/6/2026 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter. | |
| Modificada | Media (5.3) | 1.9% | 💥 Exploit | Awstats | 20/4/2018 | 17/6/2026 | A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framename and update parameters. | |
| Modificada | Media (6.1) | 0.84% | — | Jenkins Global-build-stats | 26/1/2018 | 17/6/2026 | Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability.… | |
| Modificada | Media (4.7) | 0.40% | — | Tats W3MCanonical Ubuntu Linux | 25/1/2018 | 17/6/2026 | w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files. | |
| Modificada | Alta (7.5) | 4.4% | — | Tats W3MCanonical Ubuntu Linux | 25/1/2018 | 17/6/2026 | w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. | |
| Modificada | Alta (7.5) | 2.9% | — | Tats W3MCanonical Ubuntu Linux | 25/1/2018 | 17/6/2026 | w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value. | |
| Modificada | Crítica (9.8) | 4.4% | — | AwstatsDebian Linux | 3/1/2018 | 17/6/2026 | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution. | |
| Modificada | Media (6.1) | 2.5% | 💥 Exploit | Smartertools Smarterstats | 30/9/2017 | 17/6/2026 | SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting. | |
| Modificada | Media (6.5) | 3.4% | — | Opensuse LeapOpensuse Project LeapTats W3M | 20/1/2017 | 17/6/2026 | parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag. | |
| Modificada | Media (6.5) | 3.4% | — | Opensuse LeapOpensuse Project LeapTats W3M | 20/1/2017 | 17/6/2026 | The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop and resource consumption) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.9% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.9% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.4% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.3% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.6% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (heap buffer overflow and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.4% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Tats W3M | 12/12/2016 | 17/6/2026 | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause memory corruption in certain conditions via a crafted HTML page. |