Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
119 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.35% | — | SAP Fiori LaunchpadAI | 21/9/2026 | 22/9/2026 | SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive… | |
| Pendiente de análisis | Media (6.5) | 0.38% | — | HCL Devops DeployAIHCL LaunchAI | 17/9/2026 | 18/9/2026 | HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside… | |
| Aplazada | Crítica (9.8) | 0.68% | — | GravitlauncherAI | 17/9/2026 | 24/9/2026 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | 3DS 3dexperienceAI3DS Station Launcher APPAI | 28/7/2026 | 30/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | |
| Analizada | Media (6.5) | 0.38% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 9/7/2026 | 13/7/2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system. | |
| Analizada | Media (5.5) | 0.15% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 9/7/2026 | 10/7/2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Media (4.3) | 0.30% | — | Hcltechsw HCL Devops DeployHcltechsw HCL Launch | 29/6/2026 | 2/7/2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step. | |
| Aplazada | Media (5.5) | 0.41% | — | Launch-editorAI | 22/6/2026 | 23/6/2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password… | |
| Aplazada | Media (5.5) | 0.18% | — | XianyulauncherAI | 17/6/2026 | 22/6/2026 | XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Exploitation is most… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Fiori LaunchpadAI | 9/6/2026 | 23/7/2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on… | |
| Aplazada | Media (6.5) | 0.39% | — | Slovak EID Client Ecosystem D.launcherAI | 2/6/2026 | 22/7/2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)… | |
| Aplazada | Alta (7.5) | 0.51% | — | Launch-editorAIVitejs ViteAI | 1/6/2026 | 4/9/2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has… | |
| Analizada | Crítica (9.8) | 0.66% | — | Nvidia Isaac Launchable | 26/5/2026 | 24/7/2026 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Baja (2.3) | 0.09% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the… | |
| Rechazada | Sin puntuar | — | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Aplazada | Alta (7.9) | 0.28% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 1/10/2026 | Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control… | |
| Aplazada | Media (4.4) | 0.10% | — | Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI | 20/5/2026 | 25/9/2026 | Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without… | |
| Aplazada | Alta (7.8) | 0.13% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP TAF ApplauncherAI | 12/5/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Aplazada | Media (6.9) | 0.26% | — | Ultravnc LauncherAI | 22/3/2026 | 17/6/2026 | UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of… | |
| Aplazada | Alta (7.5) | 0.65% | — | Doom LauncherAI | 16/3/2026 | 17/6/2026 | Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files | |
| Aplazada | Alta (8.1) | 0.52% | — | Launchandsell TribeAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3. | |
| Aplazada | Alta (8.5) | 0.14% | — | Acer Launch ManagerAI | 6/2/2026 | 17/6/2026 | Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute… | |
| Aplazada | Media (5.4) | 0.11% | — | Launchinteractive Merge Minify RefreshAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14. | |
| Aplazada | Alta (8.5) | 0.32% | — | Rockstargames Rockstar Games LauncherAI | 21/1/2026 | 17/6/2026 | Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access. |