Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.45% | — | Asus GamesdkAI | 15/7/2026 | 17/9/2026 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or… | |
| Aplazada | Alta (8.4) | 1.1% | — | Gotcha Gotcha Games INC RPG Maker MVAIGotcha Gotcha Games INC RPG Maker MZAI | 30/6/2026 | 30/6/2026 | RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed. | |
| Aplazada | Media (4.3) | 0.20% | — | Games CatalogAI | 20/5/2026 | 23/7/2026 | The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the gc_crud() function which handles the delete action (action=delete) via a GET request without any wp_verify_nonce() /… | |
| Aplazada | Media (4.3) | 0.19% | — | Bigfishgames SyndicateAI | 20/5/2026 | 24/7/2026 | The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigfishgames_syndicate_submenu() function. This makes it possible for unauthenticated attackers to reset plugin settings and… | |
| Aplazada | Baja (1.1) | 0.13% | — | Shinrays Games Goods Triple APPAI | 2/4/2026 | 24/7/2026 | A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown function of the file jRwTX.java of the component cats.goods.sort.sorting.games. Performing a manipulation of the argument AES_IV/AES_PASSWORD results in use of hard-coded cryptographic key . Attacking… | |
| Aplazada | Media (6.4) | 0.41% | — | WP Games EmbedAI | 21/3/2026 | 17/6/2026 | The WP Games Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [game] shortcode in all versions up to and including 0.1beta. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'width', 'height', 'src', 'title', 'description',… | |
| Aplazada | Media (6.4) | 0.36% | — | Scoreboard FOR Html5 Games LiteAI | 21/3/2026 | 17/6/2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small… | |
| Aplazada | Alta (8.5) | 0.18% | — | Take2games PreyAI | 28/1/2026 | 17/6/2026 | Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system reboot. | |
| Aplazada | Alta (8.5) | 0.32% | — | Rockstargames Rockstar Games LauncherAI | 21/1/2026 | 17/6/2026 | Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access. | |
| Aplazada | Alta (8.8) | 0.16% | — | Epic Games StoreAIMicrosoft StoreAI | 15/1/2026 | 17/6/2026 | A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges. | |
| Aplazada | Alta (8.5) | 0.18% | — | Epic Games Easy Anti CheatAI | 23/12/2025 | 17/6/2026 | Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to execute arbitrary code with elevated system privileges. Attackers can exploit the service configuration by inserting malicious code in the system root path that would execute with LocalSystem… | |
| Aplazada | Alta (7.5) | 0.49% | — | Yoyo Games GamemakerAI | 31/10/2025 | 17/6/2026 | Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_create_server() function in their projects are urged to update and recompile immediately. | |
| Analizada | Baja (1.9) | 0.22% | — | Huuugegames Huuge BOX | 8/8/2025 | 17/6/2026 | A vulnerability was found in Huuge Box App 1.0.3 on Android. It has been classified as problematic. This affects an unknown part of the file AndroidManifest.xml of the component com.huuge.game.zjbox. The manipulation leads to improper export of android application components. Local access is required to approach this… | |
| Aplazada | Baja (2) | 0.20% | — | Epic Games LauncherAI | 19/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the component Installer. The manipulation leads to untrusted search path. Attacking locally is a requirement. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.8) | 0.20% | — | Epicgames Launcher | 12/12/2024 | 17/6/2026 | Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Modificada | Media (5.3) | 0.39% | — | Silverwaregames | 25/8/2023 | 17/6/2026 | Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticeably different amount of time passes depending of whether the specified email address presents in our database or not. This has been fixed in version 1.3.7. | |
| Modificada | Media (5.3) | 0.45% | — | Silverwaregames | 25/8/2023 | 17/6/2026 | Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is associated with a member of the site. Since… | |
| Modificada | Crítica (9.8) | 1.6% | — | Robtopgames Geometry Dash | 11/7/2023 | 17/6/2026 | A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level. | |
| Modificada | Media (4.3) | 0.39% | — | Silverwaregames | 10/4/2023 | 17/6/2026 | SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19. | |
| Modificada | Crítica (9.1) | 0.69% | — | Smartconrtactgames Project Smartconrtactgames | 16/3/2023 | 17/6/2026 | An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions. | |
| Modificada | Crítica (9.8) | 0.66% | — | Flashgames Project Flashgames | 5/3/2023 | 16/6/2026 | A vulnerability was found in iGamingModules flashgames 1.1.0. It has been classified as critical. Affected is an unknown function of the file game.php. The manipulation of the argument lid leads to sql injection. It is possible to launch the attack remotely. The name of the patch is… | |
| Modificada | Alta (7.3) | 1.5% | — | Rockstargames Grand Theft Auto V | 22/1/2023 | 17/6/2026 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. | |
| Modificada | Media (5.4) | 0.34% | — | Silverwaregames | 19/12/2022 | 17/6/2026 | Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `<iframe>` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as HTML tags are being stripped. However, it… | |
| Modificada | Media (5.9) | 0.55% | — | Silverwaregames | 6/9/2022 | 17/6/2026 | SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobvious feature of PHP, hashes generated by built-in functions and starting with the `0e` symbols were being handled as zero multiplied with the `e` number. Therefore, the hash value was equal to 0. The… | |
| Modificada | Media (5.5) | 0.40% | — | Innogames GOD Kings | 28/10/2020 | 17/6/2026 | The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However, the application does not enforce… |