Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Arcadebuilder Game Portal Manager | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL commands via a usercookie cookie. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | PHP Fusion Arcade Module | 12/4/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view_game_list action. | |
| Modificada | Media (4.3) | 0.97% | — | Fredi Bach Phpmydesktop Arcade | 21/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpMyDesktop|Arcade 1.0 allows remote attackers to inject arbitrary web script or HTML via the subsite parameter in the subsite todo. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Fredi Bach Phpmydesktop Arcade | 1/6/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo. | |
| Modificada | Media (4.3) | 1.9% | — | Phparcadescript | 9/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpArcadeScript 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the gamename parameter in tellafriend.php, (2) the login_status parameter in loginbox.php, (3) the submissionstatus parameter in index.php, the (4)… | |
| Modificada | Media (6.4) | 1.0% | 💥 Exploit | Ipbproarcade | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. In addition, the demonstration… | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Ibproarcade | 16/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter. | |
| Modificada | Baja (2.6) | 1.4% | — | Realnetworks Realarcade | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Ipbproarcade | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Ipbproarcade | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the show_stats module in Arcade.php in IbProArcade allows remote attackers to execute arbitrary SQL code via the gameid parameter. | |
| Modificada | Alta (7.5) | 3.7% | — | Gamespy Arcade | 27/8/2003 | 16/6/2026 | Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code via .. (dot dot) sequences in filenames in a .APK (Zip) file. |