Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2675▼ 351 respecto a la semana anterior
Críticas / altas1301▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 272 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.29%—Themrdemonized Xray-monolith27/1/202631/8/2026
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.
ModificadaMedia (6.1)0.41%—Cththemes Monolit7/4/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.
ModificadaAlta (8.8)4.3%—Dell Idrac6 ModularDell Idrac6 Monolithic2/7/201817/6/2026
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as…
ModificadaMedia (5)19%—Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic19/12/201417/6/2026
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
ModificadaMedia (4.3)1.6%—Dell Idrac6 FirmwareDell Idrac6 MonolithicDell Idrac7 FirmwareDell Idrac724/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.
ModificadaAlta (9.3)5.2%—Monolith Productions First Encounter Assault Recon6/10/200716/6/2026
Multiple format string vulnerabilities in the Monolith Lithtech engine, as used by First Encounter Assault Recon (F.E.A.R.) 1.08 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet…
ModificadaMedia (5)5.2%—Monolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions NO ONE Lives ForeverMonolith Productions Shogo31/12/200416/6/2026
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.
ModificadaBaja (2.1)1.9%—Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
ModificadaMedia (5)3.8%—Monolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron31/12/200416/6/2026
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that…