Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Joomla BSQ Sitestats | 6/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allow remote attackers to execute arbitrary SQL commands via (1) unspecified parameters when importing the (a) ip-to-country.csv file; and the (2) HTTP Referer, (3) HTTP User Agent, and (4)… | |
| Modificada | Media (6.8) | 1.2% | — | Joomla BSQ Sitestats | 6/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled when the administrator views site statistics. | |
| Modificada | Media (6.8) | 1.2% | — | Joomla BSQ Sitestats | 6/3/2007 | 16/6/2026 | SQL injection vulnerability in Joomla BSQ Sitestats 1.8.0 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the query string, possibly PHP_SELF. | |
| Modificada | Media (6.8) | 1.2% | — | Joomla BSQ Sitestats | 6/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Ezboo Webstats | 21/2/2007 | 16/6/2026 | Ezboo webstats, possibly 3.0.3, allows remote attackers to bypass authentication and gain access via a direct request to (1) update.php and (2) config.php. | |
| Modificada | Media (5) | 1.2% | — | Apache Stats | 16/2/2007 | 16/6/2026 | Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array. | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Stats | 14/2/2007 | 16/6/2026 | Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function. | |
| Modificada | Media (6.8) | 1.2% | — | Hlstats | 8/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HLstats before 1.35 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the search class. NOTE: it is possible that this issue overlaps CVE-2006-4543.3 or CVE-2006-4454. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Miguel Nunes Call OF Duty 2 Dreamstats System | 6/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Xt-stats | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in xt_counter.php in Xt-Stats 2.3.x up to 2.4.0.b3 allows remote attackers to execute arbitrary PHP code via a URL in the server_base_dir parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Hlstats | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary SQL commands via the killLimit parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Hlstats | 28/12/2006 | 16/6/2026 | HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values of the player and playerdata[lastName][] parameters, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 1.7% | — | Mystats | 10/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter. | |
| Modificada | Media (5) | 1.4% | — | Mystats | 10/12/2006 | 16/6/2026 | mystats.php in MyStats 1.0.8 and earlier allows remote attackers to obtain the installation path via (1) details and (2) by array parameters, probably resulting in a path disclosure in an error message. | |
| Modificada | Alta (7.5) | 1.6% | — | Mystats | 10/12/2006 | 16/6/2026 | SQL injection vulnerability in mystats.php in MyStats 1.0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the details parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Acid Stats | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote attackers to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted,… | |
| Modificada | Media (5.1) | 2.4% | 💥 Exploit | Zoomstats | 28/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Joomla BSQ Sitestats | 26/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in BSQ Sitestats (bsq_sitestats) before 2.1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Hlstats | 6/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game parameter in players mode, the (2) weapon parameter in weaponinfo mode, the (3) st parameter in search mode, the (4) action parameter in actioninfo mode, and the (5) map… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Hlstats | 30/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 9.7% | 💥 Exploit | Awstats | 21/7/2006 | 16/6/2026 | awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters. | |
| Modificada | Baja (2.6) | 2.1% | — | Awstats | 21/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in awstats.pl in AWStats 6.5 build 1.857 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) refererpagesfilter, (2) refererpagesfilterex, (3) urlfilterex, (4) urlfilter, (5) hostfilter, or (6) hostfilterex parameters, a different… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | ASP Stats Generator | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | ASP Stats Generator | 23/6/2006 | 16/6/2026 | Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp. | |
| Modificada | Alta (7.5) | 1.1% | — | Arantius Vice Stats | 12/6/2006 | 16/6/2026 | SQL injection vulnerability in vs_search.php in Arantius Vice Stats before 1.0.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2006-2972. |