Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.58%—Hcltechsw HCL Launch12/12/202217/6/2026
HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches.
ModificadaAlta (7.5)0.21%—Hcltech HCL Launch Container Image31/10/202217/6/2026
The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages.
ModificadaAlta (8)0.79%—Foresightsports GC3 Launch Monitor FirmwareBushnellgolf Launch PRO Firmware13/10/202217/6/2026
Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the…
ModificadaMedia (4.8)0.60%—Mythemeshop Launcher6/9/202217/6/2026
Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress.
ModificadaMedia (5)0.17%—Samsung Game Launcher5/8/202217/6/2026
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.
ModificadaMedia (6.5)0.53%—Hcltechsw HCL Launch3/8/202217/6/2026
HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking.
ModificadaMedia (5.5)0.15%—Hcltechsw HCL Launch6/7/202217/6/2026
HCL Launch may store certain data for recurring activities in a plain text format.
ModificadaMedia (5.5)0.51%—Hcltechsw HCL Launch6/7/202217/6/2026
HCL Launch stores user credentials in plain clear text which can be read by a local user.
ModificadaMedia (6.1)1.4%💥 ExploitWelaunch Wordpress Country Selector25/4/202217/6/2026
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
ModificadaCrítica (9.8)1.7%—Flothemes Flo-launch25/4/202217/6/2026
The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.
ModificadaMedia (6.1)1.4%—SAP Fiori Launchpad10/3/202217/6/2026
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaCrítica (9.3)1.7%—Nvidia Omniverse Launcher2/2/202217/6/2026
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of…
ModificadaMedia (6.1)2.3%💥 ExploitWelaunch Wordpress Gdpr&ccpa1/2/202217/6/2026
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this…
ModificadaCrítica (9.6)2.1%—Welaunch Wordpress Gdpr&ccpa1/2/202217/6/2026
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this…
ModificadaAlta (8.8)1.7%—Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+3911/10/202117/6/2026
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the…
ModificadaCrítica (9.8)5.2%—Bitovi Launchpad1/2/202117/6/2026
All versions of package launchpad are vulnerable to Command Injection via stop.
ModificadaMedia (6.1)0.65%—SAP Fiori Launchpad (news Tile Application)13/11/202017/6/2026
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected…
ModificadaAlta (8.6)1.4%—SAP Fiori Launchpad (news Tile Application)10/11/202017/6/2026
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve…
ModificadaMedia (6.1)0.68%—SAP Fiori Launchpad9/9/202017/6/2026
SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication…
ModificadaCrítica (9.1)2.1%—Robotemi Launcher OS7/8/202017/6/2026
Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors.
ModificadaCrítica (9.8)1.0%—Google Chrome-launcher2/5/202017/6/2026
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
ModificadaMedia (6.1)0.65%—SAP Fiori Launchpad10/3/202017/6/2026
SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability.
ModificadaAlta (8.8)2.9%—Ncsoft NC Launcher29/8/201917/6/2026
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. This can be leveraged for…
ModificadaCrítica (9.8)2.3%—Ulaunchelf Project Ulaunchelf15/7/201917/6/2026
uLaunchELF < commit 170827a is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Loader program (loader.c) overly trusts the arguments provided via command line.
Orbitaley — Vulnerabilidades