Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%—PHP Arena Pafiledb10/1/200516/6/2026
paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session.
ModificadaMedia (4.3)2.6%💥 ExploitPHP Arena Pafiledb31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter.
ModificadaAlta (10)74%💥 ExploitArush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+106/12/200416/6/2026
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b…
ModificadaMedia (5)1.2%—PHP Arena Pafiledb27/4/200416/6/2026
paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message.
ModificadaMedia (4.3)1.7%💥 ExploitPHP Arena Pafiledb27/4/200416/6/2026
Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551.
ModificadaMedia (4.3)1.9%💥 ExploitPHP Arena Pafiledb31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions.
ModificadaMedia (4.3)1.2%—PHP Arena Pafiledb31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string.
ModificadaMedia (5)5.2%💥 ExploitID Software Quake 3 Arena29/7/200116/6/2026
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.
ModificadaMedia (6.4)1.3%—ID Software Quake 3 Arena3/5/200016/6/2026
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.