Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.31% | — | Welaunch Wordpress Gdpr | 19/11/2024 | 17/6/2026 | The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Crítica (9.8) | 0.49% | — | HPE Cray Parallel Application Launch Service | 13/6/2024 | 17/6/2026 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. | |
| Analizada | Media (4.3) | 0.36% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values. | |
| Analizada | Media (6.3) | 0.31% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.9) | 0.32% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type. | |
| Analizada | Media (6.1) | 0.31% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 15/4/2024 | 17/6/2026 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. | |
| Modificada | Media (5.5) | 0.21% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 3/2/2024 | 17/6/2026 | HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent. | |
| Modificada | Media (5.5) | 0.16% | — | Hcltechsw HCL Launch | 28/12/2023 | 17/6/2026 | An HCL UrbanCode Deploy Agent installed as a Windows service in a non-standard location could be subject to a denial of service attack by local accounts.. | |
| Modificada | Media (6.5) | 0.48% | — | Hcltechsw HCL Launch | 28/12/2023 | 17/6/2026 | HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Modificada | Media (5.4) | 0.31% | — | Hcltechsw HCL Launch | 21/12/2023 | 17/6/2026 | HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure. | |
| Modificada | Alta (7.5) | 0.46% | — | Hcltechsw HCL Launch | 21/12/2023 | 17/6/2026 | HCL Launch may mishandle input validation of an uploaded archive file leading to a denial of service due to resource exhaustion. | |
| Modificada | Media (4.6) | 0.40% | — | Vmware Workspace ONE Launcher | 12/12/2023 | 17/6/2026 | Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information. | |
| Modificada | Media (4.3) | 0.48% | — | SAP Fiori Launchpad | 12/12/2023 | 17/6/2026 | SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, UI_700 200, SAP_BASIS 793, allows an attacker to use HTTP verb POST on read-only service causing low impact on Confidentiality of the application. | |
| Modificada | Alta (7.8) | 0.73% | — | Plain Craft Launcher 2 Project Plain Craft Launcher 2 | 7/10/2023 | 17/6/2026 | Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information. | |
| Modificada | Media (5.5) | 0.13% | — | Samsung Gamelauncher | 6/9/2023 | 17/6/2026 | PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data. | |
| Modificada | Media (5.3) | 0.36% | — | Nvidia Omniverse Launcher | 3/8/2023 | 17/6/2026 | NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability… | |
| Modificada | Media (5.5) | 0.15% | — | Hcltechsw HCL Launch | 10/7/2023 | 17/6/2026 | HCL Launch could disclose sensitive information if a manual edit of a configuration file has been performed. | |
| Modificada | Alta (7.8) | 0.36% | — | Actionlauncher Action Launcher | 30/5/2023 | 17/6/2026 | An issue was found in Action Launcher v50.5 allows an attacker to escalate privilege via modification of the intent string to function update. | |
| Modificada | Media (5.5) | 0.34% | — | Actionlauncher Action Launcher | 30/5/2023 | 17/6/2026 | An issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to function insert. | |
| Modificada | Crítica (9.8) | 2.1% | — | Apusapps Launcher | 10/4/2023 | 17/6/2026 | An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter. | |
| Modificada | Alta (7.1) | 0.55% | — | Atlauncher | 4/4/2023 | 17/6/2026 | ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory. | |
| Modificada | Media (5.4) | 0.34% | — | Hcltechsw HCL Launch | 2/4/2023 | 17/6/2026 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to further attacks such as XSS and Open Redirections. | |
| Modificada | Alta (8.8) | 0.26% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 17/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Obox Themes Launchpad – Coming Soon & Maintenance Mode plugin <= 1.0.13 versions. | |
| Modificada | Alta (7.8) | 0.44% | — | Prismlauncher Prism Launcher | 6/3/2023 | 17/6/2026 | An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file. | |
| Modificada | Media (4.8) | 0.54% | — | Obox Launchpad - Coming Soon & Maintenance Mode Plugin | 13/1/2023 | 17/6/2026 | The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… |