uipath kayıtları
uipath üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %16,7
- Silahlaştırılmış
- 1 · %16,7
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %16,7
- Yayından KEV’e ortanca
- 16 gün
Tekrar eden sınıflar
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-506 Embedded Malicious Code1
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2026-45321Silahlaştırılmış | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keystanstack · tanstack\/arktype-adapter · CWE-506 | Kritik9,6 | KEV | %1,1 | 11 May 2026 |
40Planlayın | CVE-2021-44041İstismar yok | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI huipath · assistant · CWE-610 | Kritik9,8 | — | %1,8 | 14 Ara 2021 |
39İzleyin | CVE-2021-44042İstismar yok | An issue was discovered in UiPath Assistant 21.4.4.uipath · assistant · CWE-116 | Kritik9,8 | — | %1,1 | 14 Ara 2021 |
35İzleyin | CVE-2018-17305İstismar yok | UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leadinuipath · orchestrator · CWE-732 | Yüksek8,8 | — | %1,5 | 11 Nis 2019 |
22İzleyin | CVE-2018-19855İstismar yok | UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export featuresuipath · orchestrator · CWE-1236 | Orta5,5 | — | %1,1 | 8 Ağu 2019 |
21İzleyin | CVE-2021-44043İstismar yok | An issue was discovered in UiPath App Studio 21.4.4.uipath · app studio · CWE-79 | Orta5,4 | — | %0,5 | 14 Ara 2021 |
- CVE-2026-4532168Bu hafta
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %1tanstack · tanstack\/arktype-adapter11 May 2026
- CVE-2021-4404140Planlayın
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI h
KritikCVSS 9,8İstismar yokEPSS %2uipath · assistant14 Ara 2021
- CVE-2021-4404239İzleyin
An issue was discovered in UiPath Assistant 21.4.4.
KritikCVSS 9,8İstismar yokEPSS %1uipath · assistant14 Ara 2021
- CVE-2018-1730535İzleyin
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leadin
YüksekCVSS 8,8İstismar yokEPSS %2uipath · orchestrator11 Nis 2019
- CVE-2018-1985522İzleyin
UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features
OrtaCVSS 5,5İstismar yokEPSS %1uipath · orchestrator8 Ağu 2019
- CVE-2021-4404321İzleyin
An issue was discovered in UiPath App Studio 21.4.4.
OrtaCVSS 5,4İstismar yokEPSS %0uipath · app studio14 Ara 2021