Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Proarcadescript | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in games/game.php in ProArcadeScript allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 3.5% | — | Embarcadero Interbase SMP 2009 | 26/1/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Embarcadero Technologies InterBase SMP 2009 9.0.3.437 allow remote attackers to execute arbitrary code via unknown vectors involving crafted packets. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Turnkeyarcade Turnkey Arcade Script | 18/11/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Arcadetradescript Arcade Trade Script | 18/11/2009 | 16/6/2026 | Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Standalonearcade SAA | 15/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Phparcadescript | 14/8/2009 | 16/6/2026 | SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Freearcadescript Free Arcade Script | 14/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Arcadetradescript Arcade Trade Script | 1/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Arcadwy Arcade Script | 2/4/2009 | 16/6/2026 | SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Arcadwy Arcade Script CMS | 2/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter). | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Freearcadescript Free Arcade Script | 24/2/2009 | 16/6/2026 | Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Agares Media Arcadem PRO | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Arcadem Pro 2.700 through 2.802 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter, probably related to includes/articleblock.php. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Turnkeyarcade Turnkey Arcade Script | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a play action. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Proarcadescript | 22/9/2008 | 16/6/2026 | SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phparcadescript | 19/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Pragmaticutopia COM Puarcade | 11/4/2008 | 16/6/2026 | SQL injection vulnerability in puarcade.class.php 2.2 and earlier in the Pragmatic Utopia PU Arcade (com_puarcade) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter to index.php. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Phparcadescript | 5/3/2008 | 16/6/2026 | SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ibproarcade | 14/2/2008 | 16/6/2026 | SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Pragmatic Utopia PU Arcade | 4/1/2008 | 16/6/2026 | SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2.0.3, 2.1.2, and 2.1.3 Beta component for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter to index.php. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Agares Media Arcadem | 27/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadadminpage parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Agares Media Arcadem | 28/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Agares Media Arcadem | 28/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not. | |
| Modificada | Media (6) | 1.0% | 💥 Exploit | Getmyownarcade | 17/8/2007 | 16/6/2026 | SQL injection vulnerability in search.php in GetMyOwnArcade allows remote attackers to execute arbitrary SQL commands via the query parameter. | |
| Modificada | Alta (10) | 2.2% | — | AV Scripts AV Arcade | 10/7/2007 | 16/6/2026 | admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Avscripts AV Arcade | 4/7/2007 | 16/6/2026 | SQL injection vulnerability in includes/view_page.php in AV Arcade 2.1b allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_page action to index.php. |