Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Jirafeau | 7/7/2018 | 17/6/2026 | script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the shared files description file and allow the execution of a JavaScript payload each time an administrator searches or lists uploaded files. These two injections could be triggered… | |
| Modificada | Media (6.1) | 0.71% | — | Jirafeau | 7/7/2018 | 17/6/2026 | An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting vulnerability via the name parameter. | |
| Modificada | Alta (8.8) | 0.52% | — | Jirafeau | 7/7/2018 | 17/6/2026 | The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and search_link. | |
| Modificada | Media (6.1) | 0.71% | — | Jirafeau | 6/7/2018 | 17/6/2026 | An issue was discovered in Jirafeau before 3.4.1. The "search file by hash" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges. | |
| Modificada | Media (6.1) | 0.71% | — | Jirafeau | 6/7/2018 | 17/6/2026 | An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges. | |
| Modificada | Media (4.9) | 0.38% | — | Jirafeau | 6/7/2018 | 17/6/2026 | A CSRF issue was discovered in Jirafeau before 3.4.1. The "delete file" feature on the admin panel is not protected against automated requests and could be abused. | |
| Modificada | Alta (7.5) | 2.7% | — | Atlassian JiraAtlassian Jira Server | 16/5/2018 | 17/6/2026 | The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it. | |
| Modificada | Media (6.1) | 38% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 14/5/2018 | 17/6/2026 | The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of… | |
| Modificada | Media (5.4) | 0.92% | — | Atlassian Jira Server | 17/4/2018 | 17/6/2026 | The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in nested wiki markup. | |
| Modificada | Media (6.5) | 1.2% | — | Atlassian JiraAtlassian Jira Server | 10/4/2018 | 17/6/2026 | Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service… | |
| Modificada | Media (6.1) | 0.89% | — | Atlassian Jira | 10/4/2018 | 17/6/2026 | The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters. | |
| Modificada | Media (6.1) | 0.85% | — | Atlassian Jira | 6/4/2018 | 17/6/2026 | The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields. | |
| Modificada | Media (5.4) | 0.64% | — | Atlassian Jira | 6/4/2018 | 17/6/2026 | The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Jira | 2/2/2018 | 17/6/2026 | The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter. | |
| Modificada | Media (6.1) | 0.81% | — | Atlassian Jira | 18/1/2018 | 17/6/2026 | The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter. | |
| Modificada | Media (6.5) | 0.55% | — | Atlassian Jira | 18/1/2018 | 17/6/2026 | The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities. | |
| Modificada | Media (5.3) | 0.69% | — | Atlassian Jira | 17/1/2018 | 17/6/2026 | The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and… | |
| Modificada | Media (6.1) | 1.2% | — | Atlassian Jira | 12/1/2018 | 17/6/2026 | The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter. | |
| Modificada | Media (4.3) | 0.64% | — | Atlassian Jira | 12/1/2018 | 17/6/2026 | The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (6.1) | 1.0% | — | Atlassian JiraAtlassian Jira Server | 12/1/2018 | 17/6/2026 | The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter. | |
| Modificada | Alta (8.4) | 1.7% | — | Jiransoft AppcheckJiransoft Appcheck PRO | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in AppCheck and AppCheck Pro prior to version 2.0.1.15 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Atlassian Jira | 10/4/2017 | 17/6/2026 | The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object. | |
| Modificada | Alta (8.8) | 0.87% | — | Atlassian Jira | 10/4/2017 | 17/6/2026 | Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. | |
| Modificada | Media (4.8) | 0.78% | — | Atlassian Jira | 10/4/2017 | 17/6/2026 | Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. | |
| Modificada | Media (6.1) | 2.1% | — | Atlassian Jira | 31/1/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header. |