Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

597 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.74%—Atlassian Jira Data CenterAtlassian Jira Server12/2/202017/6/2026
The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open…
ModificadaMedia (4.3)0.81%—Atlassian Jira Data CenterAtlassian Jira Server12/2/202017/6/2026
The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulnerable to cross-site request forgery (CSRF). An attacker could exploit this by tricking an administrative user into making malicious HTTP requests, allowing the attacker to enumerate hosts and open…
ModificadaAlta (7.8)0.48%—Atlassian ConfluenceAtlassian Confluence Server6/2/202017/6/2026
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their…
ModificadaMedia (4.3)0.55%—Atlassian Jira Data CenterAtlassian Jira Server6/2/202017/6/2026
The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn the JMX monitoring flag off or on via a Cross-site request forgery (CSRF) vulnerability.
ModificadaMedia (4.3)1.3%—Atlassian Jira Data CenterAtlassian Jira Server6/2/202017/6/2026
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine project titles they do not have access to via an improper authorization vulnerability.
ModificadaMedia (5.3)1.5%—Atlassian Jira Data CenterAtlassian Jira Server6/2/202017/6/2026
The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira project key exists or not via an information disclosure vulnerability.
ModificadaMedia (4.9)0.77%—Atlassian JiraAtlassian Jira Software Data Center6/2/202017/6/2026
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability.
ModificadaMedia (6.5)0.79%—Atlassian Jira Server6/2/202017/6/2026
Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, which has not yet finished being installed, via Cross-site request forgery (CSRF) vulnerabilities.
ModificadaAlta (7.8)0.37%—Atlassian Jira Server6/2/202017/6/2026
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
ModificadaMedia (4.3)1.2%—Atlassian JiraAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Software Data Center6/2/202017/6/2026
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug.
ModificadaAlta (7.5)2.4%—Atlassian Crowd6/2/202017/6/2026
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability.
ModificadaAlta (8.8)2.5%—Atlassian Bitbucket15/1/202017/6/2026
Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3,…
ModificadaAlta (8.8)1.6%—Atlassian Bitbucket15/1/202017/6/2026
Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from…
ModificadaAlta (8.8)2.6%—Atlassian Bitbucket15/1/202017/6/2026
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version…
ModificadaMedia (6.5)1.9%—Atlassian ConfluenceAtlassian Confluence Server19/12/201917/6/2026
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in Confluence Server and Confluence Data Center. This plugin was used to facilitate communication with the Atlassian Companion application. The Confluence Previews plugin in Confluence Server and Confluence Data Center…
ModificadaMedia (4.3)1.2%—Atlassian JiraAtlassian Jira Server18/12/201917/6/2026
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing…
ModificadaMedia (4.3)0.92%—Atlassian Application Links17/12/201917/6/2026
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions…
ModificadaMedia (6.5)0.45%—Atlassian Crowd17/12/201917/6/2026
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default.
ModificadaAlta (7.5)1.1%—Atlassian Saml Single Sign ON13/12/201917/6/2026
An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 through 3.2.2 for Jira and Confluence, versions 2.4.0 through 3.0.3 for Bitbucket, and versions 2.4.0 through 2.5.2 for Bamboo. It allows locally disabled users to reactivate their accounts just by…
ModificadaMedia (4.3)0.73%—Atlassian CrucibleAtlassian Fisheye11/12/201917/6/2026
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.
ModificadaMedia (6.1)0.74%—Atlassian CrucibleAtlassian Fisheye11/12/201917/6/2026
The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the reviewedBranch parameter.
ModificadaMedia (4.8)0.60%—Atlassian CrucibleAtlassian Fisheye11/12/201917/6/2026
The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a missing branch.
ModificadaMedia (5.5)0.19%—Huawei Atlas 300 FirmwareHuawei Atlas 500 Firmware29/11/201917/6/2026
Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerability. A local, authenticated attacker may craft specific parameter and send to the process to exploit this vulnerability. Successfully exploit may cause service crash.
ModificadaMedia (6.1)1.8%💥 PoCApache Atlas18/11/201917/6/2026
Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
ModificadaMedia (4.3)1.3%—Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+48/11/201917/6/2026
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the…
Orbitaley — Vulnerabilidades