Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

119 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.35%—SAP Fiori LaunchpadAI21/9/202622/9/2026
SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, causes the browser to load attacker-controlled content from an external location. This could be used to exfiltrate sensitive…
Pendiente de análisisMedia (6.5)0.38%—HCL Devops DeployAIHCL LaunchAI17/9/202618/9/2026
HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the redaction engine may fail to mask subsequent ASCII secure values embedded inside…
AplazadaCrítica (9.8)0.68%—GravitlauncherAI17/9/202624/9/2026
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in…
Pendiente de análisisCrítica (10)0.81%—3DS 3dexperienceAI3DS Station Launcher APPAI28/7/202630/7/2026
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
AnalizadaMedia (6.5)0.38%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch9/7/202613/7/2026
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
AnalizadaMedia (5.5)0.15%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch9/7/202610/7/2026
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read by a local user.
AnalizadaMedia (4.3)0.30%—Hcltechsw HCL Devops DeployHcltechsw HCL Launch29/6/20262/7/2026
HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.
AplazadaMedia (5.5)0.41%—Launch-editorAI22/6/202623/6/2026
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password…
AplazadaMedia (5.5)0.18%—XianyulauncherAI17/6/202622/6/2026
XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Exploitation is most…
Pendiente de análisisMedia (4.2)0.17%—SAP Fiori LaunchpadAI9/6/202623/7/2026
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on…
AplazadaMedia (6.5)0.39%—Slovak EID Client Ecosystem D.launcherAI2/6/202622/7/2026
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)…
AplazadaAlta (7.5)0.51%—Launch-editorAIVitejs ViteAI1/6/20264/9/2026
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has…
AnalizadaCrítica (9.8)0.66%—Nvidia Isaac Launchable26/5/202624/7/2026
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaBaja (2.3)0.09%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the…
RechazadaSin puntuar——Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
AplazadaAlta (7.9)0.28%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/20261/10/2026
Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control…
AplazadaMedia (4.4)0.10%—Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI20/5/202625/9/2026
Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without…
AplazadaAlta (7.8)0.13%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user…
Pendiente de análisisMedia (6.1)0.29%—SAP TAF ApplauncherAI12/5/202617/6/2026
SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and…
AplazadaMedia (6.9)0.26%—Ultravnc LauncherAI22/3/202617/6/2026
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of…
AplazadaAlta (7.5)0.65%—Doom LauncherAI16/3/202617/6/2026
Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files
AplazadaAlta (8.1)0.52%—Launchandsell TribeAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LaunchandSell Tribe tribe allows PHP Local File Inclusion.This issue affects Tribe: from n/a through <= 1.7.3.
AplazadaAlta (8.5)0.14%—Acer Launch ManagerAI6/2/202617/6/2026
Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to insert malicious code that would execute…
AplazadaMedia (5.4)0.11%—Launchinteractive Merge Minify RefreshAI22/1/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.This issue affects Merge + Minify + Refresh: from n/a through <= 2.14.
AplazadaAlta (8.5)0.32%—Rockstargames Rockstar Games LauncherAI21/1/202617/6/2026
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.