Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | — | Wp-statistics WP Statistics | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 1.5% | — | IBM Spss Statistics | 14/5/2016 | 17/6/2026 | Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long… | |
| Modificada | Alta (7.8) | 0.38% | — | IBM Spss Statistics | 1/1/2016 | 17/6/2026 | IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script. | |
| Modificada | Media (6.8) | 1.9% | — | IBM Spss Statistics | 25/5/2015 | 17/6/2026 | An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Media (4.3) | 0.94% | — | External Links Click Statistics Project External Links Click Statistics | 3/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Kennziffer Statistics | 3/10/2014 | 17/6/2026 | SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014. | |
| Modificada | Media (4.3) | 1.6% | — | Zdstatistics Project Zdstatistics | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in cal/test.php in the ZdStatistics (zdstats) plugin 2.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Media (5) | 2.0% | — | Tibco Spotfire Statistics Services | 15/3/2013 | 16/6/2026 | The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request. | |
| Modificada | Media (6.8) | 0.94% | 💥 Exploit | Accscripts ACC Statistics | 25/6/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses. | |
| Modificada | Media (6.8) | 0.63% | — | Sjoerd Arendsen Simplenews Statistics | 26/10/2009 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors. | |
| Modificada | Media (6.8) | 0.61% | — | Sjoerd Arendsen Simplenews Statistics | 26/10/2009 | 16/6/2026 | Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Sjoerd Arendsen Simplenews Statistics | 26/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Accscripts ACC Statistics | 26/2/2009 | 16/6/2026 | admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin." | |
| Modificada | Alta (7.5) | 1.2% | — | Inmedias Statistics | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 0.99% | — | Inmedias Statistics | 27/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Quate Grape WEB Statistics | 25/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | X-scripts X-statistics | 1/8/2006 | 16/6/2026 | SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | X-scripts X-statistics | 1/8/2006 | 16/6/2026 | SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | RWS Statistics Counter | 28/12/2005 | 16/6/2026 | SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Mediahouse Software Statistics Server Livestats | 20/10/2000 | 16/6/2026 | Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (7.2) | 0.84% | — | Mediahouse Software Statistics Server | 30/9/1999 | 16/6/2026 | Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Mediahouse Software Statistics Server | 30/9/1999 | 16/6/2026 | Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. |