Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.53% | — | IBM Robotic Process Automation FOR Cloud PAK | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.3) | 0.31% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575. | |
| Modificada | Media (6.1) | 0.70% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 6/10/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM… | |
| Modificada | Alta (7.5) | 0.87% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAKIBM Robotic Process Automation FOR Services | 29/9/2022 | 17/6/2026 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422. | |
| Modificada | Crítica (9.8) | 1.6% | — | Nuprocess Project Nuprocess | 26/9/2022 | 17/6/2026 | NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java's ProcessBuilder isn't… | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Processmaker | 19/9/2022 | 9/7/2026 | ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate normal users to Administrators. | |
| Modificada | Crítica (9.8) | 0.77% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp342000 Firmware+32 | 12/9/2022 | 17/6/2026 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control… | |
| Modificada | Crítica (9.8) | 1.5% | — | Get-process-by-name Project Get-process-by-name | 29/8/2022 | 17/6/2026 | All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function. | |
| Modificada | Media (6.7) | 0.33% | 💥 PoC | Redhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+5 | 24/8/2022 | 17/6/2026 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML. | |
| Modificada | Alta (8.2) | 0.79% | — | Redhat Process Automation Manager | 10/8/2022 | 17/6/2026 | XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser. The software processes an XML document that can contain… | |
| Analizada | Crítica (9.8) | 0.61% | — | Redhat Process Automation Manager | 10/8/2022 | 17/6/2026 | A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts. | |
| Modificada | Crítica (9.8) | 0.78% | — | IBM Robotic Process Automation FOR Cloud PAK | 10/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. | |
| Modificada | Media (4.9) | 0.81% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 10/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | |
| Modificada | Media (6.5) | 0.64% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege management for storage provider types. IBM X-Force ID: 229962. | |
| Modificada | Media (6.5) | 0.61% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for users created via a bulk upload. IBM X-Force ID: 228888. | |
| Modificada | Alta (7.2) | 0.94% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to platform administrator through manipulation of APIs. IBM X-Force ID: 227978. | |
| Modificada | Alta (7.5) | 0.90% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentials to be exposed. IBM X-Force ID: 227288. | |
| Modificada | Media (4.3) | 0.50% | — | IBM Robotic Process Automation | 1/8/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of which they should not have access. IBM X-Force ID: 219391. | |
| Modificada | Media (4.6) | 0.33% | — | IBM Robotic Process Automation | 26/7/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machine) to obtain a login access token. IBM X-Force ID: 223019. | |
| Modificada | Alta (7.5) | 1.1% | — | Digiwin Business Process Management | 20/7/2022 | 17/6/2026 | Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection attack to access arbitrary system files. | |
| Modificada | Media (5.3) | 0.84% | — | Digiwin Business Process Management | 20/7/2022 | 17/6/2026 | Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response. | |
| Modificada | Crítica (9.8) | 1.6% | — | Digiwin Business Process Management | 20/7/2022 | 17/6/2026 | Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service. | |
| Modificada | Crítica (9.3) | 1.3% | — | Hin-eng-preprocessing Project Hin-eng-preprocessing | 11/7/2022 | 17/6/2026 | The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (4.6) | 0.27% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 24/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 24/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 227124. |