Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.40%—Openwebanalytics Open WEB AnalyticsAI25/9/202628/9/2026
A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to…
AplazadaMedia (6.9)0.84%—Openwebanalytics Open WEB AnalyticsAI8/9/202610/9/2026
A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be initiated remotely. Upgrading to version…
AplazadaMedia (5)0.41%—Openwebanalytics Open WEB AnalyticsAI15/9/202517/6/2026
Open Web Analytics (OWA) before 1.8.1 allows owa_db.php v[value] SQL injection.
ModificadaMedia (4.8)0.32%—Hitsteps WEB Analytics18/10/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hitsteps Web Analytics plugin <= 5.86 versions.
ModificadaAlta (8.8)0.21%—Hitsteps WEB Analytics13/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hitsteps Hitsteps Web Analytics plugin <= 5.86 versions.
ModificadaCrítica (9.8)99%—Openwebanalytics Open WEB Analytics18/3/202217/6/2026
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
ModificadaAlta (8.1)1.2%—Oracle WEB Analytics20/10/202117/6/2026
Vulnerability in the Oracle Web Analytics product of Oracle E-Business Suite (component: Admin). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Analytics. Successful attacks of this…
ModificadaCrítica (9.8)2.7%—Openwebanalytics Open WEB Analytics17/4/201817/6/2026
Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.
ModificadaAlta (8.8)1.1%—Openwebanalytics Open WEB Analytics20/3/201817/6/2026
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
ModificadaAlta (8.2)1.9%—Oracle WEB Analytics8/8/201717/6/2026
Vulnerability in the Oracle Web Analytics component of Oracle E-Business Suite (subcomponent: Common Libraries). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
ModificadaMedia (6.1)1.0%—Nttdata WEB Analytics Service29/12/201517/6/2026
Cross-site scripting (XSS) vulnerability in the NTT DATA Smart Sourcing JavaScript module 2003-11-26 through 2013-07-09 for Web Analytics Service allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.8%—Openwebanalytics Open WEB Analytics1/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.
ModificadaAlta (7.5)2.5%—Openwebanalytics Open WEB Analytics15/1/201417/6/2026
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base.passwordResetRequest action to index.php.
ModificadaMedia (5.1)2.7%—Openwebanalytics Open WEB Analytics8/7/201016/6/2026
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.9%—Openwebanalytics Open WEB Analytics8/7/201016/6/2026
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers to read arbitrary files via directory traversal sequences in the (1) owa_action and (2) owa_do parameters.