Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.68% | — | GravitlauncherAI | 17/9/2026 | 24/9/2026 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | 3DS 3dexperienceAI3DS Station Launcher APPAI | 28/7/2026 | 30/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution. | |
| Aplazada | Media (5.5) | 0.18% | — | XianyulauncherAI | 17/6/2026 | 22/6/2026 | XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Exploitation is most… | |
| Aplazada | Media (6.5) | 0.39% | — | Slovak EID Client Ecosystem D.launcherAI | 2/6/2026 | 22/7/2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)… | |
| Aplazada | Baja (2.3) | 0.09% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the… | |
| Rechazada | Sin puntuar | — | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Aplazada | Alta (7.9) | 0.28% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 1/10/2026 | Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control… | |
| Aplazada | Media (4.4) | 0.10% | — | Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI | 20/5/2026 | 25/9/2026 | Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without… | |
| Aplazada | Alta (7.8) | 0.13% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user… | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP TAF ApplauncherAI | 12/5/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Aplazada | Media (6.9) | 0.26% | — | Ultravnc LauncherAI | 22/3/2026 | 17/6/2026 | UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of… | |
| Aplazada | Alta (7.5) | 0.65% | — | Doom LauncherAI | 16/3/2026 | 17/6/2026 | Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files | |
| Aplazada | Alta (8.5) | 0.32% | — | Rockstargames Rockstar Games LauncherAI | 21/1/2026 | 17/6/2026 | Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access. | |
| Aplazada | Crítica (9) | 0.90% | — | 3DS 3dexperience Station Launcher APPAI | 13/10/2025 | 25/9/2026 | An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine. | |
| Aplazada | Media (5) | 0.24% | — | Cozythemes SaaslauncherAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SaasLauncher: from n/a through <= 1.3.0. | |
| Aplazada | Media (5.5) | 0.13% | — | Nvidia Omniverse LauncherAI | 31/7/2025 | 17/6/2026 | NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure. | |
| Aplazada | Crítica (9.3) | 0.14% | — | Plain Craft LauncherAI | 23/7/2025 | 17/6/2026 | PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually… | |
| Aplazada | Media (5) | 0.18% | — | Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI | 6/4/2025 | 17/6/2026 | Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access… | |
| Aplazada | Alta (7.1) | 0.39% | — | Saill Site LauncherAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saill Site Launcher site-launcher allows Reflected XSS.This issue affects Site Launcher: from n/a through <= 0.9.4. | |
| Aplazada | Baja (2) | 0.20% | — | Epic Games LauncherAI | 19/1/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the component Installer. The manipulation leads to untrusted search path. Attacking locally is a requirement. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.8) | 0.20% | — | Epicgames Launcher | 12/12/2024 | 17/6/2026 | Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Alta (7.3) | 0.21% | — | Kolide LauncherAIKolide AgentAIOsquerydAI | 3/12/2024 | 17/6/2026 | The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version 1.5.3 when launcher started storing upgraded… | |
| Modificada | Media (4.6) | 0.40% | — | Vmware Workspace ONE Launcher | 12/12/2023 | 17/6/2026 | Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information. | |
| Modificada | Alta (7.8) | 0.73% | — | Plain Craft Launcher 2 Project Plain Craft Launcher 2 | 7/10/2023 | 17/6/2026 | Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information. | |
| Modificada | Media (5.5) | 0.13% | — | Samsung Gamelauncher | 6/9/2023 | 17/6/2026 | PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data. |