Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.24% | — | WP Tournament RegistrationAI | 6/8/2025 | 17/6/2026 | The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Media (5.4) | 0.19% | — | Blakelong Tournament Bracket Generator | 26/6/2025 | 17/6/2026 | The Tournament Bracket Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bracket' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.5) | 1.6% | 💥 Exploit | Lukashuser EKC Tournament Manager | 15/5/2025 | 17/6/2026 | The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory | |
| Analizada | Media (5.4) | 0.18% | — | Lukashuser EKC Tournament Manager | 15/5/2025 | 17/6/2026 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Analizada | Media (5.4) | 0.18% | — | Lukashuser EKC Tournament Manager | 15/5/2025 | 17/6/2026 | The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Aplazada | Crítica (9.6) | 0.23% | — | Lukashuser EKC Tournament ManagerAI | 31/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: from n/a through <= 2.2.1. | |
| Modificada | Media (4.3) | 1.2% | — | Tournament Project Tournament | 6/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title. | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal TournamentFrontlines Fuel OF WAR | 19/8/2009 | 16/6/2026 | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Steve Dawson Pokermax Poker League Tournament Script | 18/10/2008 | 16/6/2026 | configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Epic Games Unreal Tournament 3 | 25/9/2008 | 16/6/2026 | Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Media (5) | 2.6% | — | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Epic Games Unreal Tournament 2004 | 31/7/2008 | 16/6/2026 | Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Epic Games Unreal EngineEpic Games Unreal TournamentEpic Games Unreal Tournament 2003 | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Arush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+10 | 6/12/2004 | 16/6/2026 | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b… | |
| Modificada | Alta (10) | 7.5% | — | Epic Games Unreal EngineEpic Games Unreal Tournament 2003 | 31/12/2003 | 16/6/2026 | Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file. | |
| Modificada | Media (5) | 1.3% | — | Epic Games Unreal Tournament Server | 2/4/2003 | 16/6/2026 | Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports 7778 or 10777. |