VYPR
Vendor

Unity3d

Products
5
CVEs
6
Across products
8
Status
Private

Products

5

Recent CVEs

6
  • CVE-2017-12939CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.05

    A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.

  • CVE-2019-9197HigDec 31, 2019
    risk 0.57cvss 8.8epss 0.04

    The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.

  • CVE-2025-59489HigOct 3, 2025
    risk 0.48cvss 7.4epss 0.01

    Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an…

  • CVE-2023-37250HigAug 20, 2023
    risk 0.46cvss 7.0epss 0.00

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of…

  • CVE-2015-9288MedJul 29, 2019
    risk 0.42cvss 6.5epss 0.01

    The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials

  • CVE-2026-54424HigJul 4, 2026
    risk 0.00cvss 8.4epss 0.00

    An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where…