Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.24% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 5/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API request modified to create additional objects. IBM X-Force ID: 224159. | |
| Modificada | Alta (7.5) | 1.0% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 5/5/2022 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By… | |
| Modificada | Media (6.5) | 0.76% | — | IBM Robotic Process Automation | 5/5/2022 | 17/6/2026 | A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to some admin pages in the Control Center IBM X-Force ID: 223029. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Robotic Process Automation With Automation Anywhere | 7/5/2021 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11.0 could allow an attacker on the network to obtain sensitive information or cause a denial of service through username enumeration. IBM X-Force ID: 190992. | |
| Modificada | Media (5.3) | 1.4% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due to missing authentication in Ignite nodes. IBM X-Force ID: 161412. | |
| Modificada | Crítica (9.8) | 2.0% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161411. | |
| Modificada | Media (5.5) | 0.28% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765. | |
| Modificada | Alta (7.1) | 0.32% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764. | |
| Modificada | Media (5.4) | 1.1% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability to make unauthorized queries or modify the LDAP content. IBM X-Force ID: 160761. | |
| Modificada | Baja (3.3) | 0.30% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-mail contents from the client debug log file. IBM X-Force ID: 160759. | |
| Modificada | Media (4.9) | 1.1% | — | IBM Robotic Process Automation With Automation Anywhere | 1/7/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain highly sensitive from the credential vault. IBM X-Force ID: 160758. | |
| Modificada | Alta (8.8) | 2.2% | — | Blueprism Robotic Process Automation | 24/5/2019 | 17/6/2026 | In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exploited to escalate privileges. The vulnerability allows for abusing the application for fraud or unauthorized access to certain information. The attack requires a valid user account to connect to the… | |
| Modificada | Media (5.4) | 0.97% | — | IBM Robotic Process Automation With Automation Anywhere | 14/3/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152671. | |
| Modificada | Media (4.9) | 2.5% | — | IBM Robotic Process Automation With Automation Anywhere | 21/2/2019 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to upload arbitrary files to the system. IBM X-Force ID: 155008. | |
| Modificada | Media (5.3) | 1.3% | — | IBM Robotic Process Automation With Automation Anywhere | 2/11/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714. | |
| Modificada | Alta (7.8) | 0.24% | — | IBM Robotic Process Automation With Automation Anywhere | 2/11/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713. | |
| Modificada | Media (5.5) | 0.37% | — | IBM Robotic Process Automation With Automation Anywhere | 2/11/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707. | |
| Modificada | Alta (8.8) | 2.9% | — | IBM Robotic Process Automation With Automation Anywhere | 2/11/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this… | |
| Modificada | Media (5.4) | 0.66% | — | IBM Robotic Process Automation With Automation Anywhere | 5/10/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to persistent cross-site scripting, caused by missing escaping of a database field. An attacker that has access to the Control Room database could exploit this vulnerability to execute script in a victim's web browser within the… | |
| Modificada | Media (6.1) | 0.89% | — | IBM Robotic Process Automation With Automation Anywhere | 5/10/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere Enterprise 10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID:… | |
| Modificada | Alta (7.7) | 2.0% | — | IBM Robotic Process Automation With Automation Anywhere | 7/6/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 10.0 could allow a remote attacker to execute arbitrary code on the system, caused by improper output encoding in an CSV export. By persuading a victim to download the CSV export, to open it in Microsoft Excel and to confirm the two security questions, an… | |
| Modificada | Alta (8.8) | 0.53% | — | IBM Robotic Process Automation With Automation Anywhere | 7/6/2018 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 141622. | |
| Modificada | Media (5.4) | 0.69% | — | IBM Robotic Process Automation With Automation Anywhere | 20/12/2017 | 17/6/2026 | IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546. |