Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Atlassian JiraAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Software Data Center | 2/2/2021 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2. | |
| Modificada | Media (4.3) | 0.87% | — | Atlassian CrucibleAtlassian Fisheye | 2/2/2021 | 17/6/2026 | Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4. | |
| Modificada | Media (5.3) | 1.1% | — | Atlassian Bamboo | 28/1/2021 | 17/6/2026 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version… | |
| Modificada | Media (6.5) | 2.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 19/1/2021 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0. | |
| Modificada | Media (5.3) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 18/1/2021 | 17/6/2026 | Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5. | |
| Modificada | Media (4.3) | 1.0% | — | Atlassian Crucible | 21/12/2020 | 17/6/2026 | Affected versions of Atlassian Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the file upload request feature of code reviews. The affected versions are before version 4.7.4, and from version 4.8.0 before 4.8.5. | |
| Modificada | Media (5.5) | 1.0% | — | Apache GroovyNetapp SnapcenterOracle Agile Engineering Data ManagementOracle Agile PLM Mcad Connector+17 | 7/12/2020 | 25/8/2026 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods… | |
| Modificada | Media (5.4) | 0.78% | — | Atlassian Automation FOR Jira | 30/11/2020 | 17/6/2026 | Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF/classes & <jira-installation>/jira/bin directories via a template injection vulnerability in Jira smart values using mustache partials. The affected versions are those… | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 25/11/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 25/11/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4. | |
| Modificada | Crítica (9.8) | 2.4% | — | Atlassian Jira Comment | 9/11/2020 | 17/6/2026 | The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment. | |
| Modificada | Crítica (9.8) | 2.9% | — | Atlassian Jira Create | 9/11/2020 | 17/6/2026 | The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue. | |
| Modificada | Media (5.3) | 1.9% | — | Atlassian JiraAtlassian Jira Server | 15/10/2020 | 17/6/2026 | Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2. | |
| Modificada | Media (5.4) | 0.94% | — | Atlassian JiraAtlassian Jira Server | 12/10/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1. | |
| Modificada | Media (4.3) | 1.3% | — | Atlassian Jira | 6/10/2020 | 17/6/2026 | Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before… | |
| Modificada | Media (5.4) | 1.1% | — | Atlassian Editor-core | 1/10/2020 | 17/6/2026 | The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets. | |
| Modificada | Alta (7.5) | 0.87% | — | Atlassian Crowd | 1/10/2020 | 17/6/2026 | Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1. | |
| Modificada | Media (4.3) | 0.85% | — | Atlassian Jira Service Desk | 21/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Service Desk Server and Data Center allow remote attackers authenticated as a non-administrator user to view Project Request-Types and Descriptions, via an Information Disclosure vulnerability in the editform request-type-fields resource. The affected versions are before version… | |
| Modificada | Media (5.3) | 76% | 💥 Exploit | Atlassian Jira Data CenterAtlassian Jira Server | 21/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names via an Information Disclosure vulnerability in the /secure/QueryComponent!Default.jspa endpoint. The affected versions are before version 8.5.8, and from version 8.6.0… | |
| Modificada | Media (6.5) | 2.2% | — | Atlassian Jira Server | 21/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial of Service (DoS) vulnerability in JQL version searching. The affected versions are before version 7.13.16; from version 7.14.0 before 8.5.7; from version 8.6.0 before… | |
| Modificada | Media (5.3) | 100% | 💥 Exploit | Atlassian Data CenterAtlassian JiraAtlassian Jira Server | 17/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0. | |
| Modificada | Media (6.1) | 2.6% | — | Apache Atlas | 16/9/2020 | 17/6/2026 | Apache Atlas before 2.1.0 contain a XSS vulnerability. While saving search or rendering elements values are not sanitized correctly and because of that it triggers the XSS vulnerability. | |
| Modificada | Alta (7.5) | 3.1% | — | Atlassian JiraAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Software Data Center | 1/9/2020 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0. | |
| Modificada | Media (6.5) | 1.0% | — | Atlassian Fisheye | 5/8/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3. | |
| Modificada | Media (5.4) | 1.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 24/7/2020 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, and from version 7.5.0 before 7.5.2. |