Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 1.8% | — | Awstats | 9/2/2005 | 16/6/2026 | awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Awstats | 18/1/2005 | 16/6/2026 | AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Psychostats | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter. | |
| Modificada | Baja (2.1) | 0.35% | — | Astats | 31/12/2004 | 16/6/2026 | aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files. | |
| Modificada | Media (5) | 1.2% | — | Uninet Statsplus | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers. | |
| Modificada | Alta (7.5) | 1.6% | — | Deepmetrix Livestats | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | |
| Modificada | Media (5) | 2.2% | — | Zorbat Zorbstats | 2/10/2001 | 16/6/2026 | Zorbat Zorbstats PHP script before 0.9 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Drummond Miles A1stats | 14/8/2001 | 16/6/2026 | Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi. | |
| Modificada | Alta (7.5) | 3.6% | — | Drummond Miles A1stats | 14/8/2001 | 16/6/2026 | a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Mediahouse Software Statistics Server Livestats | 20/10/2000 | 16/6/2026 | Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. |