Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.81%—Nvidia Isaac Launchable23/12/202517/6/2026
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.
AnalizadaCrítica (9.8)0.69%—Nvidia Isaac Launchable23/12/202517/6/2026
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.
AnalizadaCrítica (9.8)0.63%—Nvidia Isaac Launchable23/12/202517/6/2026
NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.
AnalizadaMedia (4.8)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch17/12/202517/6/2026
Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to execute malicious code in certain web pages.
AnalizadaMedia (6.1)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch17/12/202530/9/2026
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
AnalizadaMedia (5.6)0.19%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch16/12/202517/6/2026
HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.
AplazadaCrítica (9)0.90%—3DS 3dexperience Station Launcher APPAI13/10/202525/9/2026
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
AplazadaMedia (5)0.24%—Cozythemes SaaslauncherAI3/9/202517/6/2026
Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SaasLauncher: from n/a through <= 1.3.0.
AplazadaMedia (5.5)0.13%—Nvidia Omniverse LauncherAI31/7/202517/6/2026
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure.
AplazadaCrítica (9.3)0.14%—Plain Craft LauncherAI23/7/202517/6/2026
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually…
AplazadaMedia (6.5)0.19%—Texas Instruments Cc2652rb LaunchpadAITexas Instruments Simplelink Cc13xx Cc26xx SDKAI9/7/20255/7/2026
Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.
AplazadaMedia (5)0.18%—Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI6/4/202517/6/2026
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access…
AnalizadaAlta (7.6)0.26%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch3/4/202517/6/2026
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
AnalizadaAlta (7.5)0.31%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch2/4/202517/6/2026
HCL DevOps Deploy / HCL Launch could allow unauthorized access to other services or potential exposure of sensitive data due to missing authentication in its Agent Relay service.
AnalizadaMedia (5.5)0.15%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch27/3/202517/6/2026
HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.
AnalizadaAlta (7.2)0.68%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch24/3/202517/6/2026
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
AnalizadaMedia (6.5)0.27%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch24/3/202517/6/2026
HCL DevOps Deploy / HCL Launch could allow an authenticated user to obtain sensitive information about other users on the system due to missing authorization for a function.
AplazadaAlta (7.1)0.39%—Saill Site LauncherAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saill Site Launcher site-launcher allows Reflected XSS.This issue affects Site Launcher: from n/a through <= 0.9.4.
AplazadaBaja (2)0.20%—Epic Games LauncherAI19/1/202517/6/2026
A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the component Installer. The manipulation leads to untrusted search path. Attacking locally is a requirement. The complexity of an attack is rather high. The…
AplazadaCrítica (9.3)0.54%—Binarycarpenter Launchpage.app ImporterAI16/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BinaryCarpenter LaunchPage.app Importer launchpage-app-importer allows SQL Injection.This issue affects LaunchPage.app Importer: from n/a through <= 1.1.
AnalizadaAlta (7.8)0.20%—Epicgames Launcher12/12/202417/6/2026
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaMedia (5.5)0.15%—Hcltechsw HCL Launch6/12/202417/6/2026
HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.
AnalizadaMedia (6.8)0.29%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch5/12/202417/6/2026
HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.
AplazadaAlta (7.3)0.21%—Kolide LauncherAIKolide AgentAIOsquerydAI3/12/202417/6/2026
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version 1.5.3 when launcher started storing upgraded…
AnalizadaCrítica (9.1)0.45%—Welaunch Wordpress Gdpr19/11/202417/6/2026
The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to delete arbitrary users.