Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.58% | — | Hcltechsw HCL Launch | 12/12/2022 | 17/6/2026 | HCL Launch could allow a user with administrative privileges, including "Manage Security" permissions, the ability to recover a credential previously saved for performing authenticated LDAP searches. | |
| Modificada | Alta (7.5) | 0.21% | — | Hcltech HCL Launch Container Image | 31/10/2022 | 17/6/2026 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix provides directions and tools to replace the non-unique keys and certificates. This does not affect the standard installer packages. | |
| Modificada | Alta (8) | 0.79% | — | Foresightsports GC3 Launch Monitor FirmwareBushnellgolf Launch PRO Firmware | 13/10/2022 | 17/6/2026 | Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service listens on a TCP port on all interfaces and allows for process debugging, file system modification, and terminal access as the root user. In conjunction with a hosted wireless access point and the… | |
| Modificada | Media (4.8) | 0.60% | — | Mythemeshop Launcher | 6/9/2022 | 17/6/2026 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenance Mode plugin <= 1.0.11 at WordPress. | |
| Modificada | Media (5) | 0.17% | — | Samsung Game Launcher | 5/8/2022 | 17/6/2026 | Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction. | |
| Modificada | Media (6.5) | 0.53% | — | Hcltechsw HCL Launch | 3/8/2022 | 17/6/2026 | HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security checking. | |
| Modificada | Media (5.5) | 0.15% | — | Hcltechsw HCL Launch | 6/7/2022 | 17/6/2026 | HCL Launch may store certain data for recurring activities in a plain text format. | |
| Modificada | Media (5.5) | 0.51% | — | Hcltechsw HCL Launch | 6/7/2022 | 17/6/2026 | HCL Launch stores user credentials in plain clear text which can be read by a local user. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Welaunch Wordpress Country Selector | 25/4/2022 | 17/6/2026 | Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request | |
| Modificada | Crítica (9.8) | 1.7% | — | Flothemes Flo-launch | 25/4/2022 | 17/6/2026 | The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value. | |
| Modificada | Media (6.1) | 1.4% | — | SAP Fiori Launchpad | 10/3/2022 | 17/6/2026 | Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Crítica (9.8) | 18% | — | Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+89 | 21/2/2022 | 17/6/2026 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion | |
| Modificada | Crítica (9.3) | 1.7% | — | Nvidia Omniverse Launcher | 2/2/2022 | 17/6/2026 | NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of… | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Crítica (9.6) | 2.1% | — | Welaunch Wordpress Gdpr&ccpa | 1/2/2022 | 17/6/2026 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this… | |
| Modificada | Alta (8.8) | 1.7% | — | Accesspressthemes Access Demo ImporterAccesspressthemes Accesspress-liteAccesspressthemes Accesspress-magAccesspressthemes Accesspress-parallax+39 | 11/10/2021 | 17/6/2026 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the… | |
| Modificada | Crítica (9.8) | 5.2% | — | Bitovi Launchpad | 1/2/2021 | 17/6/2026 | All versions of package launchpad are vulnerable to Command Injection via stop. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Fiori Launchpad (news Tile Application) | 13/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected… | |
| Modificada | Alta (8.6) | 1.4% | — | SAP Fiori Launchpad (news Tile Application) | 10/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve… | |
| Modificada | Media (6.1) | 0.68% | — | SAP Fiori Launchpad | 9/9/2020 | 17/6/2026 | SAP Fiori Launchpad does not sufficiently encode user controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, resulting in reflected Cross-Site Scripting (XSS) vulnerability. With a successful attack, the attacker can steal authentication… | |
| Modificada | Crítica (9.1) | 2.1% | — | Robotemi Launcher OS | 7/8/2020 | 17/6/2026 | Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.0% | — | Google Chrome-launcher | 2/5/2020 | 17/6/2026 | All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Fiori Launchpad | 10/3/2020 | 17/6/2026 | SAP Fiori Launchpad, versions- 753, 754, does not sufficiently encode user-controlled inputs, and hence allowing the attacker to inject the meta tag into the launchpad html using the vulnerable parameter, leading to reflected Cross-Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 2.9% | — | Ncsoft NC Launcher2 | 9/8/2019 | 17/6/2026 | NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. This can be leveraged for… | |
| Modificada | Crítica (9.8) | 2.3% | — | Ulaunchelf Project Ulaunchelf | 15/7/2019 | 17/6/2026 | uLaunchELF < commit 170827a is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Loader program (loader.c) overly trusts the arguments provided via command line. |