Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.68%—GravitlauncherAI17/9/202624/9/2026
GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in…
Pendiente de análisisCrítica (10)0.81%—3DS 3dexperienceAI3DS Station Launcher APPAI28/7/202630/7/2026
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.
AplazadaMedia (5.5)0.18%—XianyulauncherAI17/6/202622/6/2026
XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local attack conditions. Affected versions relied on a fixed localhost redirect URI without PKCE or state validation. Exploitation is most…
AplazadaMedia (6.5)0.39%—Slovak EID Client Ecosystem D.launcherAI2/6/202622/7/2026
D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)…
AplazadaBaja (2.3)0.09%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the…
RechazadaSin puntuar——Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
AplazadaAlta (7.9)0.28%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/20261/10/2026
Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control…
AplazadaMedia (4.4)0.10%—Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI20/5/202625/9/2026
Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without…
AplazadaAlta (7.8)0.13%—Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI20/5/202625/9/2026
Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user…
Pendiente de análisisMedia (6.1)0.29%—SAP TAF ApplauncherAI12/5/202617/6/2026
SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and…
AplazadaMedia (6.9)0.26%—Ultravnc LauncherAI22/3/202617/6/2026
UltraVNC Launcher 1.2.2.4 contains a buffer overflow vulnerability in the Path vncviewer.exe property field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 300-byte payload of repeated characters through the Properties dialog to trigger a denial of…
AplazadaAlta (7.5)0.65%—Doom LauncherAI16/3/202617/6/2026
Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files
AplazadaAlta (8.5)0.32%—Rockstargames Rockstar Games LauncherAI21/1/202617/6/2026
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.
AplazadaCrítica (9)0.90%—3DS 3dexperience Station Launcher APPAI13/10/202525/9/2026
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.
AplazadaMedia (5)0.24%—Cozythemes SaaslauncherAI3/9/202517/6/2026
Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SaasLauncher: from n/a through <= 1.3.0.
AplazadaMedia (5.5)0.13%—Nvidia Omniverse LauncherAI31/7/202517/6/2026
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be written to the log files through proxy servers. A successful exploit of this vulnerability might lead to information disclosure.
AplazadaCrítica (9.3)0.14%—Plain Craft LauncherAI23/7/202517/6/2026
PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used during the third-party login process are accidentally recorded in the local log file. Although the log file is not automatically uploaded or shared, if the user manually…
AplazadaMedia (5)0.18%—Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI6/4/202517/6/2026
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access…
AplazadaAlta (7.1)0.39%—Saill Site LauncherAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in saill Site Launcher site-launcher allows Reflected XSS.This issue affects Site Launcher: from n/a through <= 0.9.4.
AplazadaBaja (2)0.20%—Epic Games LauncherAI19/1/202517/6/2026
A vulnerability classified as problematic was found in Epic Games Launcher up to 17.2.1. This vulnerability affects unknown code in the library profapi.dll of the component Installer. The manipulation leads to untrusted search path. Attacking locally is a requirement. The complexity of an attack is rather high. The…
AnalizadaAlta (7.8)0.20%—Epicgames Launcher12/12/202417/6/2026
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AplazadaAlta (7.3)0.21%—Kolide LauncherAIKolide AgentAIOsquerydAI3/12/202417/6/2026
The Kolide Agent (aka: Launcher) is the lightweight agent designed to work with Kolide's service. An implementation bug in the Kolide Agent (known as `launcher`) allows for local privilege escalation to the SYSTEM user on Windows 10 and 11. The bug was introduced in version 1.5.3 when launcher started storing upgraded…
ModificadaMedia (4.6)0.40%—Vmware Workspace ONE Launcher12/12/202317/6/2026
Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.
ModificadaAlta (7.8)0.73%—Plain Craft Launcher 2 Project Plain Craft Launcher 27/10/202317/6/2026
Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.
ModificadaMedia (5.5)0.13%—Samsung Gamelauncher6/9/202317/6/2026
PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.