Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)5.6%—Rockwellautomation Arena27/1/202017/6/2026
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to…
ModificadaMedia (6.5)1.8%—Cor-entertainment Alien-arenaDebian LinuxFedoraproject Fedora12/11/201916/6/2026
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
ModificadaAlta (7.8)5.3%—Rockwellautomation Arena24/9/201917/6/2026
In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initialized.
ModificadaCrítica (9.8)1.9%—Compact Arena Project Compact Arena9/9/201917/6/2026
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
ModificadaCrítica (9.8)1.4%—Openforis Arena26/8/201917/6/2026
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
ModificadaBaja (3.3)5.8%—Rockwellautomation Arena15/8/201917/6/2026
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.
ModificadaAlta (7.8)12%—Rockwellautomation Arena15/8/201917/6/2026
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.
ModificadaCrítica (9.8)2.3%—Arenam Amgallery19/6/201917/6/2026
SQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
ModificadaMedia (5.5)2.0%—Rockwellautomation Arena14/5/201817/6/2026
Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..
ModificadaMedia (6.1)1.0%—NTT Webarena Service Formmail5/6/201617/6/2026
Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)2.1%—Ioquake3 EngineOpenarenaTremulous27/10/201416/6/2026
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
ModificadaMedia (5.4)0.27%—Mavenhut Solitaire Arena9/9/201417/6/2026
The Solitaire Arena (aka com.mavenhut.solitaire) application 1.0.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (10)8.7%—Ioquake3 EngineOpenarenaSmokin-guns Smokin' GunsTremulous+24/8/201116/6/2026
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted…
ModificadaAlta (7.5)4.2%—Ioquake3 EngineOpenarenaWorldofpadman World OF Padman4/8/201116/6/2026
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
ModificadaAlta (10)7.6%—Icculus Alien Arena13/1/201016/6/2026
Stack-based buffer overflow in the M_AddToServerList function in client/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers to execute arbitrary code via a packet with a crafted server description to UDP port 27901 followed by a packet with a long print command.
ModificadaMedia (5)2.2%—COR Entertainment Alien Arena 20078/9/200716/6/2026
Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to a client. NOTE: client IP addresses are available via product-specific queries.
ModificadaAlta (7.5)4.8%💥 ExploitCOR Entertainment Alien Arena 20078/9/200716/6/2026
Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in a nickname.
ModificadaAlta (7.5)1.0%💥 ExploitPHP Arena Pabugs8/8/200716/6/2026
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.
ModificadaAlta (7.5)2.5%💥 ExploitPHP Arena Pafiledb17/7/200716/6/2026
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000.
ModificadaAlta (7.5)2.7%💥 ExploitPHP Arena Pabugs29/9/200616/6/2026
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.
ModificadaAlta (7.5)3.2%💥 ExploitMxbb PortalPHP Arena Pafiledb15/5/200616/6/2026
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
ModificadaAlta (7.6)7.6%💥 ExploitID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory8/5/200616/6/2026
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.
ModificadaMedia (6.4)1.2%💥 ExploitPHP Arena Pacheckbook5/5/200616/6/2026
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third…
ModificadaMedia (6.5)4.5%💥 ExploitCOR Entertainment Alien Arena 200610/3/200616/6/2026
Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code via unspecified vectors when the server sends crafted messages to the clients.
ModificadaMedia (6.5)5.2%💥 ExploitCOR Entertainment Alien Arena 200610/3/200616/6/2026
Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server.
Orbitaley — Vulnerabilidades