Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · uipath

uipath

· 3 Critical

Total CVEs

6

Critical

3

Products

69

Search All CVEs →

6

Products (69)

assistant2 CVEsorchestrator2 CVEsuipath\/access-policy-tool1 CVEsuipath\/admin-tool1 CVEsuipath\/agent-sdk1 CVEsuipath\/agent-tool1 CVEsuipath\/agent.sdk1 CVEsuipath\/aops-policy-tool1 CVEsuipath\/ap-chat1 CVEsuipath\/api-workflow-tool1 CVEsuipath\/apollo-core1 CVEsuipath\/apollo-react1 CVEsuipath\/apollo-wind1 CVEsuipath\/auth1 CVEsuipath\/case-tool1 CVEsuipath\/cli1 CVEsuipath\/codedagent-tool1 CVEsuipath\/codedagents-tool1 CVEsuipath\/codedapp-tool1 CVEsuipath\/common1 CVEsuipath\/context-grounding-tool1 CVEsuipath\/data-fabric-tool1 CVEsuipath\/docsai-tool1 CVEsuipath\/filesystem1 CVEsuipath\/flow-tool1 CVEsuipath\/functions-tool1 CVEsuipath\/gov-tool1 CVEsuipath\/identity-tool1 CVEsuipath\/insights-sdk1 CVEsuipath\/insights-tool1 CVEsuipath\/integrationservice-sdk1 CVEsuipath\/integrationservice-tool1 CVEsuipath\/llmgw-tool1 CVEsuipath\/maestro-sdk1 CVEsuipath\/maestro-tool1 CVEsuipath\/orchestrator-tool1 CVEsuipath\/packager-tool-apiworkflow1 CVEsuipath\/packager-tool-bpmn1 CVEsuipath\/packager-tool-case1 CVEsuipath\/packager-tool-connector1 CVEsuipath\/packager-tool-flow1 CVEsuipath\/packager-tool-functions1 CVEsuipath\/packager-tool-webapp1 CVEsuipath\/packager-tool-workflowcompiler1 CVEsuipath\/packager-tool-workflowcompiler-browser1 CVEsuipath\/platform-tool1 CVEsuipath\/project-packager1 CVEsuipath\/resource-tool1 CVEsuipath\/resourcecatalog-tool1 CVEsuipath\/resources-tool1 CVEsuipath\/robot1 CVEsuipath\/rpa-legacy-tool1 CVEsuipath\/rpa-tool1 CVEsuipath\/solution-packager1 CVEsuipath\/solution-tool1 CVEsuipath\/solutionpackager-sdk1 CVEsuipath\/solutionpackager-tool-core1 CVEsuipath\/tasks-tool1 CVEsuipath\/telemetry1 CVEsuipath\/test-manager-tool1 CVEsuipath\/tool-workflowcompiler1 CVEsuipath\/traces-tool1 CVEsuipath\/ui-widgets-multi-file-upload1 CVEsuipath\/uipath-python-bridge1 CVEsuipath\/vertical-solutions-tool1 CVEsuipath\/vss1 CVEsapp studio1 CVEsuipath\/widget.sdk1 CVEsuipath\/access-policy-sdk1 CVEs

Recent Vulnerabilities

View all 6
CVE-2026-45321CRITICAL 9.6KEV

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.

CVE-2021-44043MEDIUM 5.4

An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.

CVE-2021-44042CRITICAL 9.8

An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

CVE-2021-44041CRITICAL 9.8

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

CVE-2018-19855

UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.

CVE-2018-17305

UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.