Products: 69
    Vulnerabilities: 6
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-45321

    Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys

    Last Modified: May 29, 2026
    Published: May 12, 2026

    CVE-2021-44043

    An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload functionality for uploading icons when attempting to create new Apps. An attacker with minimal privileges in the application can build their own App and upload a malicious file containing an XSS payload, by uploading an arbitrary file and modifying the MIME type in a subsequent HTTP request. This then allows the file to be stored and retrieved from the server by other users in the same organization.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2021-44041

    UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2021-44042

    An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application.

    Last Modified: Nov 21, 2024
    Published: Dec 14, 2021

    CVE-2018-19855

    UiPath Orchestrator before 2018.3.4 allows CSV Injection, related to the Audit export, Robot log export, and Transaction log export features.

    Last Modified: Nov 21, 2024
    Published: Aug 08, 2019
    Items Per Page