Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.8% | — | Atlassian Jira Server | 13/8/2019 | 17/6/2026 | The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability. | |
| Analizada | Crítica (9.8) | 85% | ⚠ Explotación activa💥 Exploit | Atlassian Jira Server | 9/8/2019 | 17/6/2026 | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0… | |
| Modificada | Media (5.4) | 0.76% | — | Atlassian Jira | 9/8/2019 | 17/6/2026 | The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the country parameter. | |
| Modificada | Media (4.3) | 0.85% | — | Atlassian Jira | 9/8/2019 | 17/6/2026 | The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check. | |
| Modificada | Crítica (9.8) | 16% | 💥 PoC | Softwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+27 | 26/7/2019 | 17/6/2026 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. | |
| Modificada | Media (6.5) | 1.5% | — | Atlassian Jira | 26/6/2019 | 17/6/2026 | The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name". | |
| Modificada | Alta (8.8) | 4.9% | — | Atlassian Sourcetree | 14/6/2019 | 17/6/2026 | An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI. | |
| Modificada | Crítica (9.1) | 4.4% | — | Atlassian Bitbucket | 3/6/2019 | 17/6/2026 | Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed… | |
| Analizada | Crítica (9.8) | 95% | ⚠ Explotación activa💥 Exploit | Atlassian Crowd | 3/6/2019 | 17/6/2026 | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthenticated or authenticated requests to a Crowd or Crowd Data Center instance can exploit this vulnerability to install arbitrary plugins, which permits remote code execution… | |
| Modificada | Alta (8.1) | 2.6% | — | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass… | |
| Modificada | Alta (7.5) | 60% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check. | |
| Modificada | Media (5.3) | 53% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | |
| Modificada | Media (6.1) | 8.9% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter. | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Jira Server | 3/5/2019 | 17/6/2026 | The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter. | |
| Modificada | Media (6.1) | 38% | 💥 Exploit | Atlassian Jira | 3/5/2019 | 17/6/2026 | The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Atlassian JiraAtlassian Jira Server | 30/4/2019 | 17/6/2026 | The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check. | |
| Modificada | Media (5.4) | 3.3% | — | Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+4 | 30/4/2019 | 17/6/2026 | Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl… | |
| Analizada | Alta (8.8) | 97% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Server | 18/4/2019 | 17/6/2026 | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal… | |
| Modificada | Alta (8.7) | 1.6% | — | Atlassian Application Links | 29/3/2019 | 17/6/2026 | The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version 5.2.6 used an XML document builder that was vulnerable to XXE when consuming a client OAuth request. This allowed malicious oauth application linked applications to probe… | |
| Modificada | Media (6.5) | 1.2% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect. | |
| Modificada | Alta (7.2) | 2.3% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another… | |
| Modificada | Alta (8.1) | 1.4% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability. |