Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | ASP Stats Generator | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | ASP Stats Generator | 23/6/2006 | 16/6/2026 | Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp. | |
| Modificada | Alta (7.5) | 1.1% | — | Arantius Vice Stats | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972. | |
| Modificada | Alta (7.5) | 1.4% | — | Arantius Vice Stats | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in vs_resource.php in Arantius Vice Stats 0.5b and 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (4) | 2.7% | — | Awstats | 30/5/2006 | 16/6/2026 | AWStats 6.5, and possibly other versions, allows remote authenticated users to execute arbitrary code by using the configdir parameter to awstats.pl to upload a configuration file whose name contains shell metacharacters, then access that file using the LogFile directive. | |
| Modificada | Media (5.1) | 58% | 💥 Exploit | Awstats | 8/5/2006 | 16/6/2026 | The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter. | |
| Modificada | Baja (2.6) | 4.9% | 💥 Exploit | Awstats | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732. | |
| Modificada | Media (5) | 1.8% | — | Php-stats | 9/3/2006 | 16/6/2026 | PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request to checktables.php, which lists the database table_prefix. | |
| Modificada | Alta (7.5) | 1.5% | — | Php-stats | 9/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the option[prefix] parameter in admin.php and other unspecified PHP scripts, and (2) the PC_REMOTE_ADDR HTTP header to click.php. | |
| Modificada | Alta (10) | 3.5% | — | Php-stats | 9/3/2006 | 16/6/2026 | admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password. | |
| Modificada | Media (6.5) | 1.8% | — | Php-stats | 9/3/2006 | 16/6/2026 | Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the option_new[compatibility_mode] parameter, which is not filtered before being stored in config.php. NOTE: this… | |
| Modificada | Alta (7.5) | 2.2% | — | Php-stats | 9/3/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) option[language] and (2) option[template] parameters, and (3) possibly other parameters, to (a) admin.php and (b) other unspecified scripts.… | |
| Modificada | Alta (7.5) | 1.4% | — | Gamerz Wp-stats | 18/1/2006 | 16/6/2026 | SQL injection vulnerability in wp-stats.php in GaMerZ WP-Stats 2.0 allows remote attackers to execute arbitrary SQL commands via the author parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Woah-projekt Phgstats | 11/1/2006 | 16/6/2026 | phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable. | |
| Modificada | Alta (7.5) | 1.1% | — | Mroovca Stats | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in mroovca stats (mroovcastats) before 0.4.5b has unknown attack vectors and impact, related to cookies. | |
| Modificada | Media (5) | 1.7% | — | Awstats | 30/8/2005 | 16/6/2026 | AWStats 6.4, and possibly earlier versions, allows remote attackers to obtain sensitive information via a file that does not exist in the config parameter, which reveals the path in an error message. | |
| Modificada | Media (5) | 3.0% | — | AwstatsCanonical Ubuntu LinuxDebian Linux | 15/8/2005 | 16/6/2026 | Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call. | |
| Modificada | Alta (7.5) | 2.9% | — | Denora IRC Stats | 7/8/2005 | 16/6/2026 | Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code. | |
| Modificada | Baja (2.1) | 0.33% | — | Remstats | 2/5/2005 | 16/6/2026 | remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Awstats | 2/5/2005 | 16/6/2026 | Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Awstats | 2/5/2005 | 16/6/2026 | awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Awstats | 2/5/2005 | 16/6/2026 | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Awstats | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Awstats | 2/5/2005 | 16/6/2026 | awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog. | |
| Modificada | Alta (7.5) | 1.9% | — | Remstats | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising." |