Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

257 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 ExploitMitchell Sleeper L4D Stats16/3/201016/6/2026
SQL injection vulnerability in player.php in Left 4 Dead (L4D) Stats 1.1 allows remote attackers to execute arbitrary SQL commands via the steamid parameter.
ModificadaMedia (4.3)0.87%—Surfstats5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
ModificadaAlta (7.5)1.1%—JOS DE Ruijter Superseriousstats17/11/200916/6/2026
SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote attackers to execute arbitrary SQL commands via the uid parameter, related to an "incorrect regexp." NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.6)4.9%—Tatsuhiro Tsujikawa Aria220/10/200916/6/2026
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details…
ModificadaAlta (10)5.8%—Tatsuhiro Tsujikawa Aria27/10/200916/6/2026
Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)2.0%💥 ExploitThehockeystop Hockeystats Online26/8/200916/6/2026
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php.
ModificadaMedia (5)2.2%💥 ExploitR2newsletter R2 Newsletter LiteR2newsletter R2 Newsletter PROR2newsletter R2 Newsletter Stats27/7/200916/6/2026
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.
ModificadaAlta (7.5)2.0%—Edgewall FirestatsFirestats22/6/200916/6/2026
SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)2.8%—Firestats22/6/200916/6/2026
PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.
ModificadaAlta (7.5)0.95%💥 ExploitScivox VSP Stats Processor2/4/200916/6/2026
SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.
ModificadaMedia (4.3)1.1%—Denorastats Phpdenora10/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitPsychostats6/3/200916/6/2026
Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.
ModificadaAlta (7.5)0.97%💥 ExploitUltrastats24/2/200916/6/2026
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary SQL commands via the serverid parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhp-stats20/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno parameters in a systems action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)2.5%💥 ExploitRobotstats20/2/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in RobotStats 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter to (1) graph.php and (2) robotstats.inc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (4.3)1.1%—Awstats3/12/200816/6/2026
awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter. NOTE: this issue exists because of an incomplete fix for CVE-2008-3714.
ModificadaAlta (7.5)2.6%💥 ExploitMywebland Mystats22/10/200816/6/2026
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.
ModificadaAlta (7.5)1.0%💥 ExploitMywebland Mystats22/10/200816/6/2026
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
ModificadaMedia (5)1.2%—Denora IRC Stats25/9/200816/6/2026
Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a crafted CTCP response.
ModificadaAlta (9.3)53%💥 ExploitTelartis BV Awstats Totals4/9/200816/6/2026
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.
ModificadaMedia (4.3)1.3%—Telartis BV Awstats Totals4/9/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.
ModificadaMedia (4.3)5.6%💥 ExploitAwstats19/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.8 allows remote attackers to inject arbitrary web script or HTML via the query_string, a different vulnerability than CVE-2006-3681 and CVE-2006-1945.
ModificadaAlta (7.5)2.1%💥 ExploitUltrastats21/7/200816/6/2026
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhpstats24/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.
ModificadaAlta (7.5)1.1%—Xoops XM Memberstats28/2/200816/6/2026
Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
Orbitaley — Vulnerabilidades