Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.3% | — | PHP Arena Pafiledb | 10/1/2005 | 16/6/2026 | paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | PHP Arena Pafiledb | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Arush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+10 | 6/12/2004 | 16/6/2026 | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b… | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 27/4/2004 | 16/6/2026 | paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | PHP Arena Pafiledb | 27/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | PHP Arena Pafiledb | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pafiledb.php in PHP Arena paFileDB 1.1.3 through 3.0 allows remote attackers to inject arbitrary web script or HTML via the query string in the (1) rate, (2) email, or (3) download actions. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Arena Pafiledb | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP Arena paFileDB 1.1.3 and 2.1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the search string. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | ID Software Quake 3 Arena | 29/7/2001 | 16/6/2026 | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters. | |
| Modificada | Media (6.4) | 1.3% | — | ID Software Quake 3 Arena | 3/5/2000 | 16/6/2026 | Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack. |