Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.91% | — | Mythemeshop Launcher | 13/5/2019 | 17/6/2026 | Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via fields as follows: (1) Title, (2) Favicon, (3) Meta Description, (4) Subscribe Form (Name field label, Last name field label, Email field label),… | |
| Modificada | Alta (7.5) | 2.1% | — | Wplaunchpad WpbackupplusOpensuse Leap | 7/5/2019 | 17/6/2026 | The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive information from server folders and files, as demonstrated by download.sql. | |
| Modificada | Alta (8.8) | 3.0% | — | Epicgames Launcher | 24/1/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.5) | 0.99% | — | Cmcm CM Launcher 3D | 15/8/2018 | 17/6/2026 | Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key. | |
| Modificada | Alta (8.1) | 1.7% | — | Webdriver-launcher Project Webdriver-launcher | 4/6/2018 | 17/6/2026 | webdriver-launcher is a Node.js Selenium Webdriver Launcher. webdriver-launcher downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the… | |
| Modificada | Media (5.3) | 1.2% | — | SAP BI Launchpad | 14/2/2018 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server. | |
| Modificada | Alta (7.8) | 0.40% | — | Vmware Airwatch Launcher | 16/11/2017 | 17/6/2026 | VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionality and privilege. Successful exploitation of this issue could result in an escalation of privilege. | |
| Modificada | Alta (8.1) | 1.9% | — | TOR Browser Launcher Project TOR Browser Launcher | 7/2/2017 | 17/6/2026 | Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file with the valid tarball and signature. | |
| Modificada | Crítica (9.8) | 3.5% | — | Canonical Ubuntu-core-launcher | 13/5/2016 | 17/6/2026 | The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting with "ubuntu-core." | |
| Modificada | Media (5.4) | 0.27% | — | Golauncher Dreamland Super Theme GO Gold | 19/9/2014 | 17/6/2026 | The Dreamland Super Theme GO Gold (aka com.gau.go.launcherex.viptheme.dreamland.gold) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Launchpad Ignition | 28/12/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the blog parameter to (1) comment.php and (2) view.php. | |
| Modificada | Alta (9.3) | 4.1% | — | Particlesoftware Intralaunch | 13/4/2009 | 16/6/2026 | Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | Gateway Weblaunch | 10/1/2008 | 16/6/2026 | Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method. NOTE: some of these details are… | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Gateway Cweblaunchctl Activex ControlGateway Weblaunch | 10/1/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are… | |
| Modificada | Media (5.8) | 8.7% | 💥 Exploit | HP Info CenterHP Quick Launch Button | 13/12/2007 | 16/6/2026 | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, allows remote attackers to read arbitrary registry values via the arguments to the GetRegValue method. | |
| Modificada | Alta (9.3) | 8.4% | 💥 Exploit | HP Info CenterHP Quick Launch Button | 13/12/2007 | 16/6/2026 | The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the… | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | HP Info CenterHP Quick Launch Button | 13/12/2007 | 16/6/2026 | Absolute path traversal vulnerability in the HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier allows remote attackers to execute arbitrary programs via the first argument to the LaunchApp… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Soholaunch PRO Edition | 8/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Soholaunch Pro Edition 4.9 r46 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[docroot_path] parameter to (1) includes/shared_functions.php or (2)… | |
| Modificada | Alta (7.5) | 1.7% | — | Bosanova Launcher400IBM Client AccessMochasoft Tn5250Powerterm Interconnect | 2/5/2005 | 16/6/2026 | AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by STRPCCMD (Start PC command), as… |