Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.7%—Wp-statistics WP Statistics28/4/201717/6/2026
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)1.5%—IBM Spss Statistics14/5/201617/6/2026
Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long…
ModificadaAlta (7.8)0.38%—IBM Spss Statistics1/1/201617/6/2026
IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users to gain privileges by modifying a script.
ModificadaMedia (6.8)1.9%—IBM Spss Statistics25/5/201517/6/2026
An unspecified ActiveX control in IBM SPSS Statistics 22.0 through FP1 on 32-bit platforms allows remote attackers to execute arbitrary code via a crafted HTML document.
ModificadaMedia (4.3)0.94%—External Links Click Statistics Project External Links Click Statistics3/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the External links click statistics (outstats) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.7%—Kennziffer Statistics3/10/201417/6/2026
SQL injection vulnerability in the Statistics (ke_stats) extension before 1.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, as exploited in the wild in February 2014.
ModificadaMedia (4.3)1.6%—Zdstatistics Project Zdstatistics2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in cal/test.php in the ZdStatistics (zdstats) plugin 2.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
ModificadaMedia (5)2.0%—Tibco Spotfire Statistics Services15/3/201316/6/2026
The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.
ModificadaMedia (6.8)0.94%💥 ExploitAccscripts ACC Statistics25/6/201016/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Acc Statistics 1.1 allow remote attackers to hijack the authentication of administrators for requests that change (1) passwords, (2) usernames, and (3) e-mail addresses.
ModificadaMedia (6.8)0.63%—Sjoerd Arendsen Simplenews Statistics26/10/200916/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.
ModificadaMedia (6.8)0.61%—Sjoerd Arendsen Simplenews Statistics26/10/200916/6/2026
Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)1.1%—Sjoerd Arendsen Simplenews Statistics26/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.
ModificadaAlta (7.5)2.7%💥 ExploitAccscripts ACC Statistics26/2/200916/6/2026
admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie cookie to "admin."
ModificadaAlta (7.5)1.2%—Inmedias Statistics27/5/200816/6/2026
Multiple SQL injection vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)0.99%—Inmedias Statistics27/5/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Statistics (aka ke_stats) extension 0.1.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)39%💥 ExploitQuate Grape WEB Statistics25/4/200816/6/2026
PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.
ModificadaAlta (7.5)1.4%—X-scripts X-statistics1/8/200616/6/2026
SQL injection vulnerability in x-statistics.php in X-Scripts X-Statistics 1.20 allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
ModificadaAlta (7.5)1.3%💥 ExploitX-scripts X-statistics1/8/200616/6/2026
SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.
ModificadaAlta (7.5)1.2%—RWS Statistics Counter28/12/200516/6/2026
SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaAlta (7.5)3.7%💥 ExploitMediahouse Software Statistics Server Livestats20/10/200016/6/2026
Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.
ModificadaAlta (7.2)0.84%—Mediahouse Software Statistics Server30/9/199916/6/2026
Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.
ModificadaMedia (5)7.0%💥 ExploitMediahouse Software Statistics Server30/9/199916/6/2026
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.