Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.97%—Microsoft Minecraft Bedrock Dedicated Server14/7/202622/7/2026
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
AplazadaMedia (4.3)0.34%—Openshift DedicatedAIOpenshift HiveAI19/3/202517/6/2026
A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive timespan for the spec.hibernateAfter value. If a…
AplazadaAlta (8.8)0.49%—Redhat Openshift DedicatedAIRedhat HiveAI31/12/202417/6/2026
A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod.
AplazadaAlta (8.8)0.76%—Redhat Openshift DedicatedAI19/12/202417/6/2026
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to…
ModificadaMedia (4.4)0.19%—Intel Iris XE MAX Dedicated Graphics16/2/202317/6/2026
Uncaught exception in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1436(v2) may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Iris XE MAX Dedicated Graphics16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.26%—Intel Iris XE MAX Dedicated Graphics17/11/202117/6/2026
Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 before version 27.20.100.9466 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.3%—Amxmodx AMX MOD XValve Software Half-life Dedicated Server30/10/200716/6/2026
Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified input related to geolocation, which triggers an error message from the (1) geoip_code2 or (2) geoip_code3 function, leading to a buffer…
ModificadaMedia (4.3)1.2%—Valve Software Half-life Dedicated ServerValve Software Webmod Plugin16/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the redir parameter.
ModificadaAlta (7.8)1.7%—Michal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server25/8/200716/6/2026
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address.
ModificadaMedia (5)3.5%—Michal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server25/8/200716/6/2026
Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a client denial of service (crash) via (1) a long string to the file transfer port or (2) a long chat message, or (3) a server denial of service (continuous beep and slowdown) via a string containing many…
ModificadaMedia (4)2.6%—Valve Software Half-life Cstrike Dedicated Server16/2/200616/6/2026
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.6 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a backslash character at the end of a connection string to UDP port 27015.
ModificadaMedia (5)1.5%—Gamespy Roger WilcoGamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical ServerGamespy Roger Wilco Mark31/12/200416/6/2026
The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)5.7%—Gamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server31/12/200416/6/2026
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.
ModificadaMedia (5)1.6%—Valve Software Half-lifeValve Software Half-life Dedicated Server27/7/200416/6/2026
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
ModificadaMedia (5.2)2.6%—Valve Software Half-life Cstrike Dedicated Server31/12/200316/6/2026
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infinite loop and daemon hang) via a certain connection string to UDP port 27015 that represents "absence of player informations," a related…
ModificadaAlta (7.5)9.2%—Gamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server17/9/200316/6/2026
Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers to cause a denial of service and execute arbitrary code via a client request with a large length value.
ModificadaMedia (5)3.2%—Valve Software Half-lifeValve Software Half-life Dedicated Server4/10/200216/6/2026
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out.
ModificadaAlta (7.5)2.3%—Sierra Half-lifeValve Software Half-life Dedicated Server27/6/200116/6/2026
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.
ModificadaAlta (10)3.5%—Valve Software Half-life Dedicated Server19/12/200023/9/2026
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
ModificadaAlta (10)3.8%—Valve Software Half-life Dedicated Server19/12/200023/9/2026
Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.