Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 3.5% | 💥 Exploit | Awstats | 2/12/2010 | 16/6/2026 | Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Smartertools Smarterstats | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Wapplersystems WS Stats | 22/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Clausvb DL Stats | 23/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Clausvb DL Stats | 23/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mitchell Sleeper L4D Stats | 16/3/2010 | 16/6/2026 | SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter. | |
| Modificada | Media (4.3) | 0.87% | — | Surfstats | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue. | |
| Modificada | Alta (7.5) | 1.1% | — | JOS DE Ruijter Superseriousstats | 17/11/2009 | 16/6/2026 | SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote attackers to execute arbitrary SQL commands via the uid parameter, related to an "incorrect regexp." NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Thehockeystop Hockeystats Online | 26/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | R2newsletter R2 Newsletter LiteR2newsletter R2 Newsletter PROR2newsletter R2 Newsletter Stats | 27/7/2009 | 16/6/2026 | R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb. | |
| Modificada | Alta (7.5) | 2.0% | — | Edgewall FirestatsFirestats | 22/6/2009 | 16/6/2026 | SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.8% | — | Firestats | 22/6/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Scivox VSP Stats Processor | 2/4/2009 | 16/6/2026 | SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Denorastats Phpdenora | 10/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Psychostats | 6/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ultrastats | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Php-stats | 20/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno parameters in a systems action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Robotstats | 20/2/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 1.1% | — | Awstats | 3/12/2008 | 16/6/2026 | awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Mywebland Mystats | 22/10/2008 | 16/6/2026 | hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mywebland Mystats | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | |
| Modificada | Media (5) | 1.2% | — | Denora IRC Stats | 25/9/2008 | 16/6/2026 | Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a crafted CTCP response. | |
| Modificada | Alta (9.3) | 53% | 💥 Exploit | Telartis BV Awstats Totals | 4/9/2008 | 16/6/2026 | awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function. | |
| Modificada | Media (4.3) | 1.3% | — | Telartis BV Awstats Totals | 4/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | Awstats | 19/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945. |