Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 ExploitASP Stats Generator13/7/200616/6/2026
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.
ModificadaMedia (4)2.3%💥 ExploitASP Stats Generator23/6/200616/6/2026
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
ModificadaAlta (7.5)1.1%—Arantius Vice Stats12/6/200616/6/2026
SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972.
ModificadaAlta (7.5)1.4%—Arantius Vice Stats12/6/200616/6/2026
SQL injection vulnerability in vs_resource.php in Arantius Vice Stats 0.5b and 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaMedia (4)2.7%—Awstats30/5/200616/6/2026
AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive.
ModificadaMedia (5.1)58%💥 ExploitAwstats8/5/200616/6/2026
The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.
ModificadaBaja (2.6)4.9%💥 ExploitAwstats20/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.
ModificadaMedia (5)1.8%—Php-stats9/3/200616/6/2026
PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix.
ModificadaAlta (7.5)1.5%—Php-stats9/3/200616/6/2026
Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.php.
ModificadaAlta (10)3.5%—Php-stats9/3/200616/6/2026
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.
ModificadaMedia (6.5)1.8%—Php-stats9/3/200616/6/2026
Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this…
ModificadaAlta (7.5)2.2%—Php-stats9/3/200616/6/2026
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters, to (a) admin.php and (b) other unspecified scripts.…
ModificadaAlta (7.5)1.4%—Gamerz Wp-stats18/1/200616/6/2026
SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter.
ModificadaAlta (7.5)3.1%💥 ExploitWoah-projekt Phgstats11/1/200616/6/2026
phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.
ModificadaAlta (7.5)1.1%—Mroovca Stats31/12/200516/6/2026
Unspecified vulnerability in mroovca stats (mroovcastats) before 0.4.5b has unknown attack vectors and impact, related to cookies.
ModificadaMedia (5)1.7%—Awstats30/8/200516/6/2026
AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message.
ModificadaMedia (5)3.0%—AwstatsCanonical Ubuntu LinuxDebian Linux15/8/200516/6/2026
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
ModificadaAlta (7.5)2.9%—Denora IRC Stats7/8/200516/6/2026
Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.
ModificadaBaja (2.1)0.33%—Remstats2/5/200516/6/2026
remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.5)7.0%💥 ExploitAwstats2/5/200516/6/2026
Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.
ModificadaAlta (7.5)2.0%—Awstats2/5/200516/6/2026
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
ModificadaMedia (5)3.8%💥 ExploitAwstats2/5/200516/6/2026
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
ModificadaAlta (7.5)1.8%—Awstats2/5/200516/6/2026
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
ModificadaMedia (5)7.4%💥 ExploitAwstats2/5/200516/6/2026
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.
ModificadaAlta (7.5)1.9%—Remstats2/5/200516/6/2026
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
Orbitaley — Vulnerabilidades