Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.5%—Epicgames Unreal Engine9/3/200916/6/2026
Format string vulnerability in the Epic Games Unreal engine client, as used in multiple games, allows remote servers to execute arbitrary code via (1) the CLASS parameter in a DLMGR command, (2) a malformed package (PKG), and possibly (3) the LEVEL parameter in a WELCOME command.
ModificadaAlta (7.8)3.7%💥 ExploitEpic Games Unreal Tournament 325/9/200816/6/2026
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaMedia (5)2.6%—Epic Games Unreal Tournament 331/7/200816/6/2026
Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c.
ModificadaAlta (7.5)11%💥 ExploitEpic Games Unreal Tournament 331/7/200816/6/2026
Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c.
ModificadaMedia (5)7.7%💥 ExploitEpic Games Unreal Tournament 200431/7/200816/6/2026
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.
ModificadaMedia (4.3)1.2%💥 ExploitPegames26/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in template2.php in PEGames allow remote attackers to inject arbitrary web script or HTML via the (1) sitetitle, (2) sitenav, (3) sitemain, and (4) sitealt parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third…
ModificadaMedia (4.3)1.5%💥 Exploit4shared Starsgames Control Panel27/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Starsgames Control Panel 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the st parameter.
ModificadaAlta (7.5)2.7%💥 ExploitTpvgames Mpcs18/5/200816/6/2026
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1.
ModificadaMedia (6.8)1.0%💥 ExploitPnflashgames30/4/200816/6/2026
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.
ModificadaAlta (9.3)7.5%💥 ExploitID Software Doom 3ID Software Quake 4Take2games Prey6/10/200716/6/2026
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers…
ModificadaAlta (7.5)6.1%💥 ExploitImmersion Games Cellfactor Revolution12/9/200716/6/2026
Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet.
ModificadaAlta (7.5)3.7%—Immersion Games Cellfactor Revolution12/9/200716/6/2026
Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname.
ModificadaMedia (5)3.8%💥 ExploitEpic Games Unreal Engine21/8/200716/6/2026
Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.
ModificadaMedia (5)1.7%—Epic Games Unreal Engine21/8/200716/6/2026
The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and…
ModificadaAlta (10)4.2%💥 ExploitRcms PRO Rgamescript PRO25/7/200716/6/2026
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
ModificadaAlta (7.5)1.2%💥 ExploitFlashgamescript10/7/200716/6/2026
SQL injection vulnerability in index.php in FlashGameScript 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a member action.
ModificadaAlta (7.5)1.2%💥 ExploitGamesitescript10/7/200716/6/2026
SQL injection vulnerability in index.php in GameSiteScript (gss) 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the params parameter, related to missing input validation of the id field.
ModificadaAlta (7.5)1.2%💥 ExploitXoops Flashgames Module9/5/200716/6/2026
SQL injection vulnerability in game.php in the Flashgames 1.0.1 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the lid parameter.
ModificadaAlta (7.5)3.6%💥 ExploitPnflashgames2/5/200716/6/2026
SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)3.3%💥 ExploitFlashgamescript22/2/200716/6/2026
PHP remote file inclusion vulnerability in index.php in FlashGameScript 1.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the func parameter.
ModificadaAlta (7.5)2.6%💥 ExploitMxbb Activity Games Module18/12/200616/6/2026
PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
ModificadaAlta (7.5)2.7%💥 ExploitPegames1/12/200616/6/2026
index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct PHP remote file inclusion attacks via the abs_url parameter, which is later extracted to overwrite a previously uncontrolled value.
ModificadaMedia (4.3)1.8%💥 ExploitTpvgames Mpcs23/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.
ModificadaBaja (2.6)1.3%—Cynical Games Shoutbook19/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters.
ModificadaBaja (2.6)1.2%—Cynical Games Shoutbook19/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Orbitaley — Vulnerabilidades