Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)95%⚠ Explotación activa💥 ExploitAtlassian Crowd3/6/201917/6/2026
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution…
ModificadaMedia (5.4)3.3%—Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+430/4/201917/6/2026
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl…
ModificadaMedia (6.5)1.6%—Jenkins Crowd Integration4/4/201917/6/2026
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.5)1.2%—Atlassian Crowd29/3/201917/6/2026
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability.
ModificadaMedia (6.1)1.1%—Atlassian Crowd29/3/201917/6/2026
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect.
ModificadaAlta (7.2)2.3%—Atlassian Crowd29/3/201917/6/2026
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.
ModificadaAlta (7.5)1.2%—Atlassian Crowd29/3/201917/6/2026
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another…
ModificadaAlta (8.1)1.4%—Atlassian Crowd29/3/201917/6/2026
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability.
ModificadaMedia (5.3)1.9%—Advance Crowdfunding Script Project Advance Crowdfunding Script21/3/201917/6/2026
PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory.
ModificadaMedia (6.1)1.6%—Microweber21/3/201917/6/2026
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
ModificadaAlta (8.1)1.5%—Atlassian Crowd13/2/201917/6/2026
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.
ModificadaMedia (4.9)1.1%—Atlassian Crowd29/1/201917/6/2026
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources.
ModificadaAlta (7.8)0.31%—Atlassian Crowd29/1/201917/6/2026
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.
ModificadaMedia (6.5)0.77%—Atlassian Crowd29/1/201917/6/2026
An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.
ModificadaMedia (6.1)1.3%—Microweber20/12/201817/6/2026
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.
ModificadaAlta (8.8)0.78%—Microweber16/9/201817/6/2026
An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user.
ModificadaAlta (7.5)1.1%—Crowdnext Project Crowdnext9/7/201817/6/2026
The mintToken function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Hyipcrowdsale1 Project Hyipcrowdsale19/7/201817/6/2026
The mint function of a smart contract implementation for HYIPCrowdsale1, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.0%—Crowdnext Project Crowdnext5/7/201817/6/2026
The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
ModificadaMedia (5.5)0.29%—Crowbar Project Crowbar8/6/201816/6/2026
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.
ModificadaMedia (6.8)0.57%—Atlassian Crowd31/1/201817/6/2026
The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following…
ModificadaCrítica (9.8)4.4%💥 ExploitRealestate Crowdfunding Script Project Realestate Crowdfunding Script13/12/201717/6/2026
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitCrowdfunding Script Project Crowdfunding Script13/12/201717/6/2026
FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
ModificadaAlta (7.5)0.60%—Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+1022/11/201717/6/2026
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and…
ModificadaCrítica (9.8)4.7%—Atlassian Crowd9/12/201617/6/2026
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
Orbitaley — Vulnerabilidades