Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Ultrastats | 21/7/2008 | 16/6/2026 | SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpstats | 24/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Xoops XM Memberstats | 28/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 0.87% | — | Xoops Xm-memberstats | 28/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability index.php in the XM-Memberstats (xmmemberstats) module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the sortby parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | AstatsproJoomla COM Astatspro | 22/2/2008 | 16/6/2026 | SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | AstatsproJoomla COM Astatspro | 20/2/2008 | 16/6/2026 | SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 2.9% | 💥 Exploit | Php-stats | 14/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter. | |
| Modificada | Alta (8.5) | 3.9% | 💥 Exploit | Php-stats | 14/10/2007 | 16/6/2026 | Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options record in the _options table, which is used in an eval function call by (1) admin.php, (2) click.php, (3) download.php, and unspecified… | |
| Modificada | Media (6.8) | 1.1% | — | Myipacng-stats | 1/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in init.php in Jens Tkotz myIpacNG-stats (MINGS) 0.05 allows remote attackers to execute arbitrary PHP code via a URL in the MINGS_BASE parameter. NOTE: this issue is disputed by CVE because MINGS_BASE is defined before use | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Php-stats | 17/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online action, a different vector than CVE-2007-4334. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Php-stats | 14/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP parameter. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Wp-feedstats Wordpress Plugin | 31/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Sitetrafficstats | 17/7/2007 | 16/6/2026 | SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Skeltoac Automattic Stats | 20/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer field. | |
| Modificada | Media (4.3) | 1.5% | — | Psychostats | 30/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PsychoStats 3.0.6b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) awards.php, (2) login.php, (3) register.php, (4) weapons.php, and possibly other unspecified files. | |
| Modificada | Alta (9.3) | 1.8% | — | Hlstats | 24/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007-0840 and CVE-2007-2812. | |
| Modificada | Media (4.3) | 2.7% | — | Hlstats | 22/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.35, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the action parameter. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Psychostats | 21/5/2007 | 16/6/2026 | PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Libstats | 21/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rInfo[content] parameter. | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Aimstats | 22/4/2007 | 16/6/2026 | Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into config.php via the number parameter in an update action. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aimstats | 22/4/2007 | 16/6/2026 | Static code injection vulnerability in process.php in AimStats 3.2 and earlier allows remote attackers to inject PHP code into config.php via the databasehost parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Cnstats | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PHP code via a URL in the bn parameter to (1) who_r.php or (2) who_s.php in reports/. NOTE: the provenance of this information is unknown;… | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Cnstats | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.php in reports/. | |
| Modificada | Alta (10) | 1.8% | — | TIM Soderstrom Statsdawg | 21/3/2007 | 16/6/2026 | templates/config/mail.tpl in Tim Soderstrom StatsDawg 0.92 allows remote attackers to execute arbitrary programs by specifying the program name in the qshapeLocation parameter. | |
| Modificada | Alta (10) | 3.8% | 💥 Exploit | Php-stats | 20/3/2007 | 16/6/2026 | Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php. |