Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Numbers & Addition! Math Games | 9/9/2014 | 17/6/2026 | The Numbers & Addition! Math games (aka air.com.tribalnova.ilearnwith.ipad.App2En) application 1.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Alphabet & Spelling Kids Games | 9/9/2014 | 17/6/2026 | The Alphabet & Spelling Kids Games (aka air.com.tribalnova.ilearnwith.ipad.App1En) application 1.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Animals! Kids Preschool Games | 9/9/2014 | 17/6/2026 | The Animals! Kids Preschool Games (aka air.com.tribalnova.Animals) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Little Games Africa Memory | 9/9/2014 | 17/6/2026 | The Africa Memory (aka air.com.klon4enabor4e.AfricaMemory) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Differencegames Hidden Object - Alice Free | 9/9/2014 | 17/6/2026 | The Hidden Object - Alice Free (aka air.com.differencegames.hovisionsofalicefree) application 1.0.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Differencegames Hidden Memory - Aladdin Free! | 9/9/2014 | 17/6/2026 | The Hidden Memory - Aladdin FREE! (aka air.com.differencegames.hmaladdinfree) application 1.0.31 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Topgames TOP Games Script | 29/7/2013 | 16/6/2026 | SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Bandainamcogames Madomagi-ip Android | 4/6/2012 | 16/6/2026 | The Puella Magi Madoka Magica iP application 1.05 and earlier for Android places cleartext Twitter credentials in a log file, which allows remote attackers to obtain sensitive information via a crafted application. | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Jooforge COM Gamesbox | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in the JOOFORGE Gamesbox (com_gamesbox) component 1.0.2, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a consoles action to index.php. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Dev.pucit.edu.pk COM Arcadegames | 4/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Gamescript | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ekith COM DCS Flashgames | 6/4/2010 | 16/6/2026 | SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Commodityrentals Video Games Rentals | 23/2/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Yoflash COM Mochigames | 28/1/2010 | 16/6/2026 | SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Indianpulses COM Gameserver | 28/1/2010 | 16/6/2026 | SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | COM Lucygames | 18/1/2010 | 16/6/2026 | SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bpowerhouse Bpgames | 30/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php. | |
| Modificada | Alta (10) | 9.9% | 💥 Exploit | Gameservers GSC | 8/9/2009 | 16/6/2026 | GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Indianpulses COM Gameserver | 3/9/2009 | 16/6/2026 | SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php. | |
| Modificada | Alta (9.3) | 3.4% | — | 2kgames Vietcong 2 | 21/8/2009 | 16/6/2026 | Format string vulnerability in the CNS_AddTxt function in logs.dll in 2K Games Vietcong 2 1.10 and earlier might allow remote attackers to execute arbitrary code via format string specifiers in the nickname. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal TournamentFrontlines Fuel OF WAR | 19/8/2009 | 16/6/2026 | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mygamescript MY Game Script | 29/5/2009 | 16/6/2026 | SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Chinagames Igame | 28/5/2009 | 16/6/2026 | Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are… |