Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.5% | — | Epicgames Unreal Engine | 9/3/2009 | 16/6/2026 | Format string vulnerability in the Epic Games Unreal engine client, as used in multiple games, allows remote servers to execute arbitrary code via (1) the CLASS parameter in a DLMGR command, (2) a malformed package (PKG), and possibly (3) the LEVEL parameter in a WELCOME command. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Epic Games Unreal Tournament 3 | 25/9/2008 | 16/6/2026 | Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Media (5) | 2.6% | — | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Epic Games Unreal Tournament 2004 | 31/7/2008 | 16/6/2026 | Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Pegames | 26/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | 4shared Starsgames Control Panel | 27/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Tpvgames Mpcs | 18/5/2008 | 16/6/2026 | admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1. | |
| Modificada | Media (6.8) | 1.0% | 💥 Exploit | Pnflashgames | 30/4/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action. | |
| Modificada | Alta (9.3) | 7.5% | 💥 Exploit | ID Software Doom 3ID Software Quake 4Take2games Prey | 6/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers… | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. | |
| Modificada | Alta (7.5) | 3.7% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Epic Games Unreal Engine | 21/8/2007 | 16/6/2026 | Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII. | |
| Modificada | Media (5) | 1.7% | — | Epic Games Unreal Engine | 21/8/2007 | 16/6/2026 | The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and… | |
| Modificada | Alta (10) | 4.2% | 💥 Exploit | Rcms PRO Rgamescript PRO | 25/7/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Flashgamescript | 10/7/2007 | 16/6/2026 | SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Gamesitescript | 10/7/2007 | 16/6/2026 | SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Xoops Flashgames Module | 9/5/2007 | 16/6/2026 | SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Pnflashgames | 2/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Flashgamescript | 22/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Mxbb Activity Games Module | 18/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Pegames | 1/12/2006 | 16/6/2026 | index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Tpvgames Mpcs | 23/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter. | |
| Modificada | Baja (2.6) | 1.3% | — | Cynical Games Shoutbook | 19/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters. | |
| Modificada | Baja (2.6) | 1.2% | — | Cynical Games Shoutbook | 19/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |