Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 5.6% | — | Rockwellautomation Arena | 27/1/2020 | 17/6/2026 | A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to… | |
| Modificada | Media (6.5) | 1.8% | — | Cor-entertainment Alien-arenaDebian LinuxFedoraproject Fedora | 12/11/2019 | 16/6/2026 | It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command. | |
| Modificada | Alta (7.8) | 5.3% | — | Rockwellautomation Arena | 24/9/2019 | 17/6/2026 | In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initialized. | |
| Modificada | Crítica (9.8) | 1.9% | — | Compact Arena Project Compact Arena | 9/9/2019 | 17/6/2026 | An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read. | |
| Modificada | Crítica (9.8) | 1.4% | — | Openforis Arena | 26/8/2019 | 17/6/2026 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. | |
| Modificada | Baja (3.3) | 5.8% | — | Rockwellautomation Arena | 15/8/2019 | 17/6/2026 | Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation. | |
| Modificada | Alta (7.8) | 12% | — | Rockwellautomation Arena | 15/8/2019 | 17/6/2026 | Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code. | |
| Modificada | Crítica (9.8) | 2.3% | — | Arenam Amgallery | 19/6/2019 | 17/6/2026 | SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter. | |
| Modificada | Media (5.5) | 2.0% | — | Rockwellautomation Arena | 14/5/2018 | 17/6/2026 | Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data.. | |
| Modificada | Media (6.1) | 1.0% | — | NTT Webarena Service Formmail | 5/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.1% | — | Ioquake3 EngineOpenarenaTremulous | 27/10/2014 | 16/6/2026 | server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request. | |
| Modificada | Media (5.4) | 0.27% | — | Mavenhut Solitaire Arena | 9/9/2014 | 17/6/2026 | The Solitaire Arena (aka com.mavenhut.solitaire) application 1.0.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 8.7% | — | Ioquake3 EngineOpenarenaSmokin-guns Smokin' GunsTremulous+2 | 4/8/2011 | 16/6/2026 | The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (7.5) | 4.2% | — | Ioquake3 EngineOpenarenaWorldofpadman World OF Padman | 4/8/2011 | 16/6/2026 | sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable. | |
| Modificada | Alta (10) | 7.6% | — | Icculus Alien Arena | 13/1/2010 | 16/6/2026 | Stack-based buffer overflow in the M_AddToServerList function in client/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers to execute arbitrary code via a packet with a crafted server description to UDP port 27901 followed by a packet with a long print command. | |
| Modificada | Media (5) | 2.2% | — | COR Entertainment Alien Arena 2007 | 8/9/2007 | 16/6/2026 | Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | COR Entertainment Alien Arena 2007 | 8/9/2007 | 16/6/2026 | Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | PHP Arena Pabugs | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | PHP Arena Pafiledb | 17/7/2007 | 16/6/2026 | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | PHP Arena Pabugs | 29/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Mxbb PortalPHP Arena Pafiledb | 15/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Alta (7.6) | 7.6% | 💥 Exploit | ID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory | 8/5/2006 | 16/6/2026 | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | PHP Arena Pacheckbook | 5/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third… | |
| Modificada | Media (6.5) | 4.5% | 💥 Exploit | COR Entertainment Alien Arena 2006 | 10/3/2006 | 16/6/2026 | Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code via unspecified vectors when the server sends crafted messages to the clients. | |
| Modificada | Media (6.5) | 5.2% | 💥 Exploit | COR Entertainment Alien Arena 2006 | 10/3/2006 | 16/6/2026 | Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server. |