Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 513 respecto a la semana anterior
Críticas / altas1299▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | IBM Robotic Process Automation | 20/6/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. | |
| Modificada | Media (6.5) | 0.74% | — | IBM Robotic Process Automation | 17/6/2022 | 17/6/2026 | IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294. | |
| Modificada | Media (6.5) | 0.36% | — | IBM Business Automation WorkflowIBM Business Process Manager | 31/5/2022 | 17/6/2026 | IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3, 18.0.0.0 through 18.0.0.1, IBM Business Automation Workflow containers V21.0.1 - V21.0.3 20.0.0.1 through 20.0.0.2, IBM Business Process Manager 8.6.0.0 through 8.6.0.201803, and 8.5.0.0 through… | |
| Modificada | Media (5.5) | 0.25% | — | Intel Core Processors FirmwareIntel Pentium Processors FirmwareIntel Celeron Processors FirmwareIntel Xeon Processors Firmware+4 | 12/5/2022 | 17/6/2026 | Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 1.3% | — | IBM Robotic Process Automation | 12/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 223022. | |
| Modificada | Media (5.4) | 1.0% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 9/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. | |
| Modificada | Media (4.6) | 0.24% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 5/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 5/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By… | |
| Modificada | Media (6.5) | 0.76% | — | IBM Robotic Process Automation | 5/5/2022 | 17/6/2026 | A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. | |
| Modificada | Media (5.9) | 0.63% | — | Oracle Banking Trade Finance Process Management | 19/4/2022 | 17/6/2026 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.… | |
| Modificada | Crítica (9.8) | 2.4% | — | ATT XmillSchneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 14/4/2022 | 17/6/2026 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file can lead to remote code execution. This is not the same as any of: CVE-2021-21810, CVE-2021-21811, CVE-2021-21812, CVE-2021-21815, CVE-2021-21825, CVE-2021-21826, CVE-2021-21828, CVE-2021-21829, or… | |
| Modificada | Alta (7.8) | 26% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process ExpertSchneider-electric Remoteconnect | 13/4/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file is loaded in the engineering software.… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring Cloud FunctionOracle Banking BranchOracle Banking Cash ManagementOracle Banking Corporate Lending Process Management+24 | 1/4/2022 | 17/6/2026 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | |
| Modificada | Alta (7.5) | 1.0% | — | Redhat Business-centralRedhat Descision ManagerRedhat Process Automation | 1/4/2022 | 17/6/2026 | It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. | |
| Modificada | Media (4.9) | 0.93% | — | IBM Business Automation WorkflowIBM Business Process Manager | 18/3/2022 | 17/6/2026 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user credentials in plain clear text which can be read by a lprivileged user. IBM X-Force ID: 214346. | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Redhat Descision ManagerRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion PackRedhat Process Automation+1 | 11/3/2022 | 17/6/2026 | A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability. | |
| Modificada | Media (5.9) | 0.86% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 9/3/2022 | 17/6/2026 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software, when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Process… | |
| Modificada | Crítica (9.8) | 2.7% | — | Image Processing Project Image ProcessingDebian Linux | 1/3/2022 | 17/6/2026 | image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called… | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Processwire | 24/2/2022 | 17/6/2026 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Modificada | Media (5.4) | 0.48% | — | IBM Cloud PAK FOR AutomationIBM Workflow Process Service | 21/12/2021 | 17/6/2026 | IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 212357. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Business Automation WorkflowIBM Business Process ManagerIBM Workflow Process Service | 21/12/2021 | 17/6/2026 | IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a privileged user to obtain highly sensitive information due to improper access controls. IBM X-Force ID: 209607. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Business Automation WorkflowIBM Business Process ManagerIBM Workflow Process Service | 21/12/2021 | 17/6/2026 | IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… |