Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Atlassian Crowd | 3/6/2019 | 17/6/2026 | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution… | |
| Modificada | Media (5.4) | 3.3% | — | Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+4 | 30/4/2019 | 17/6/2026 | Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl… | |
| Modificada | Media (6.5) | 1.6% | — | Jenkins Crowd Integration | 4/4/2019 | 17/6/2026 | Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.5) | 1.2% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect. | |
| Modificada | Alta (7.2) | 2.3% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another… | |
| Modificada | Alta (8.1) | 1.4% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability. | |
| Modificada | Media (5.3) | 1.9% | — | Advance Crowdfunding Script Project Advance Crowdfunding Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | |
| Modificada | Media (6.1) | 1.6% | — | Microweber | 21/3/2019 | 17/6/2026 | Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Alta (8.1) | 1.5% | — | Atlassian Crowd | 13/2/2019 | 17/6/2026 | Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability. | |
| Modificada | Media (4.9) | 1.1% | — | Atlassian Crowd | 29/1/2019 | 17/6/2026 | Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources. | |
| Modificada | Alta (7.8) | 0.31% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2. | |
| Modificada | Media (6.5) | 0.77% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings. | |
| Modificada | Media (6.1) | 1.3% | — | Microweber | 20/12/2018 | 17/6/2026 | Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code. | |
| Modificada | Alta (8.8) | 0.78% | — | Microweber | 16/9/2018 | 17/6/2026 | An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user. | |
| Modificada | Alta (7.5) | 1.1% | — | Crowdnext Project Crowdnext | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Hyipcrowdsale1 Project Hyipcrowdsale1 | 9/7/2018 | 17/6/2026 | The mint function of a smart contract implementation for HYIPCrowdsale1, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Crowdnext Project Crowdnext | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Media (5.5) | 0.29% | — | Crowbar Project Crowbar | 8/6/2018 | 16/6/2026 | The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data. | |
| Modificada | Media (6.8) | 0.57% | — | Atlassian Crowd | 31/1/2018 | 17/6/2026 | The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Realestate Crowdfunding Script Project Realestate Crowdfunding Script | 13/12/2017 | 17/6/2026 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Crowdfunding Script Project Crowdfunding Script | 13/12/2017 | 17/6/2026 | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | |
| Modificada | Alta (7.5) | 0.60% | — | Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+10 | 22/11/2017 | 17/6/2026 | Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and… | |
| Modificada | Crítica (9.8) | 4.7% | — | Atlassian Crowd | 9/12/2016 | 17/6/2026 | The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. |