Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.14% | — | Redhat Process Automation Manager | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling.… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+6 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing… | |
| Modificada | Crítica (9.1) | 0.89% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Data GridRedhat Fuse+5 | 27/3/2026 | 21/9/2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to… | |
| Modificada | Crítica (9.6) | 1.3% | — | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 5/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Modificada | Alta (7.5) | 2.3% | — | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 5/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… | |
| Analizada | Media (4.3) | 0.22% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 14/4/2025 | 17/6/2026 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Robotic Process Automation FOR Cloud PAK | 22/1/2025 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 18/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side… | |
| Analizada | Media (6.7) | 0.15% | — | IBM Robotic Process Automation | 18/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A… | |
| Analizada | Media (5.9) | 0.28% | — | IBM Robotic Process Automation | 12/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks. | |
| Analizada | Media (4.6) | 0.24% | — | IBM Robotic Process Automation | 19/12/2024 | 17/6/2026 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials. | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… | |
| Modificada | Media (4.6) | 0.29% | — | IBM Robotic Process Automation | 12/2/2024 | 17/6/2026 | IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293. | |
| Modificada | Media (6.5) | 0.54% | — | IBM Robotic Process Automation FOR Cloud PAK | 3/11/2023 | 17/6/2026 | A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.66% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 6/10/2023 | 17/6/2026 | IBM Robotic Process Automation 23.0.9 is vulnerable to privilege escalation that affects ownership of projects. IBM X-Force ID: 247527. | |
| Modificada | Media (5.3) | 0.49% | — | IBM Robotic Process Automation | 20/9/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.8 could disclose sensitive information from access to RPA scripts, workflows and related data. IBM X-Force ID: 261606. | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat Decision ManagerRedhat DroolsRedhat Jboss Middleware Text-only AdvisoriesRedhat Process Automation | 11/9/2023 | 17/6/2026 | A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server. | |
| Modificada | Media (5.3) | 0.48% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 runtime is vulnerable to information disclosure of script content if the remote REST request computer policy is enabled. IBM X-Force ID: 263470. | |
| Modificada | Crítica (9.8) | 0.70% | — | IBM Robotic Process Automation | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. | |
| Modificada | Media (4.3) | 0.49% | — | IBM Robotic Process Automation | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 server could allow an authenticated user to view sensitive information from installation logs. IBM X-Force Id: 262293. | |
| Modificada | Media (4.3) | 0.53% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 22/8/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7 server could allow an authenticated user to view sensitive information from application logs. IBM X-Force ID: 262289. |