Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Server | 25/3/2019 | 17/6/2026 | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows… | |
| Modificada | Crítica (9.8) | 6.7% | — | Atlassian ConfluenceAtlassian Confluence Server | 25/3/2019 | 17/6/2026 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from… | |
| Modificada | Alta (8.8) | 6.4% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker could send a malicious URI to a victim using Sourcetree for Windows to exploit this issue to gain code execution on the system. | |
| Modificada | Alta (8.8) | 6.7% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution… | |
| Modificada | Alta (8.8) | 5.9% | — | Atlassian Sourcetree | 8/3/2019 | 17/6/2026 | There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the… | |
| Modificada | Media (5.4) | 0.90% | — | Atlassian CrucibleAtlassian Fisheye | 20/2/2019 | 17/6/2026 | The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the wbuser parameter. | |
| Modificada | Media (4.8) | 0.89% | — | Atlassian CrucibleAtlassian Fisheye | 20/2/2019 | 17/6/2026 | The administrative linker functionality in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the href parameter. | |
| Modificada | Alta (8.1) | 1.5% | — | Atlassian Crowd | 13/2/2019 | 17/6/2026 | Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability. | |
| Modificada | Media (6.5) | 1.7% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 13/2/2019 | 17/6/2026 | Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature. | |
| Modificada | Media (5.4) | 0.91% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the… | |
| Modificada | Media (4.1) | 1.1% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before… | |
| Modificada | Media (5.4) | 0.94% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when… | |
| Modificada | Media (4.9) | 1.1% | — | Atlassian Crowd | 29/1/2019 | 17/6/2026 | Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources. | |
| Modificada | Media (6.5) | 1.8% | — | Atlassian Universal Plugin Manager | 18/1/2019 | 17/6/2026 | The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in… | |
| Modificada | Alta (7.8) | 0.31% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2. | |
| Modificada | Media (6.5) | 0.77% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings. | |
| Modificada | Media (6.5) | 1.6% | — | Atlassian Hipchat | 9/1/2019 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 1.1% | — | Atlassian Hipchat | 9/1/2019 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing… | |
| Modificada | Alta (8.8) | 1.9% | — | Atlassian Sourcetree | 5/11/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on… | |
| Modificada | Alta (8.8) | 1.9% | — | Atlassian Sourcetree | 5/11/2018 | 17/6/2026 | There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the… | |
| Modificada | Media (6.1) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before… | |
| Modificada | Media (6.1) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version… | |
| Modificada | Media (4.7) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version… | |
| Modificada | Alta (7.8) | 0.26% | — | Atlassian CrucibleAtlassian Fisheye | 16/10/2018 | 17/6/2026 | The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory. | |
| Modificada | Media (6.5) | 0.53% | — | Atlassian CrucibleAtlassian Fisheye | 18/9/2018 | 17/6/2026 | The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit settings via a Cross-site request forgery (CSRF) vulnerability. |