Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Atlassian Bamboo | 12/10/2017 | 17/6/2026 | Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have… | |
| Modificada | Alta (8.8) | 3.7% | 💥 PoC | Atlassian Bamboo | 3/10/2017 | 17/6/2026 | Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource. | |
| Modificada | Alta (8.8) | 1.7% | — | Atlassian Bamboo | 14/6/2017 | 17/6/2026 | Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability,… | |
| Modificada | Crítica (9.8) | 7.1% | — | Atlassian Bamboo | 2/8/2016 | 17/6/2026 | Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization. | |
| Modificada | Crítica (9.1) | 2.8% | — | Atlassian Bamboo | 8/2/2016 | 17/6/2026 | Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive information, modify settings, or manage build agents via unknown vectors involving the JMS port. | |
| Modificada | Crítica (9.8) | 3.0% | — | Atlassian Bamboo | 8/2/2016 | 17/6/2026 | An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port. | |
| Modificada | Crítica (9.8) | 2.3% | — | Atlassian Bamboo | 8/2/2016 | 17/6/2026 | The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an XMPP message. | |
| Modificada | Crítica (9.1) | 66% | 💥 Exploit | Atlassian BambooAtlassian ConfluenceAtlassian Confluence ServerAtlassian Crowd+3 | 22/5/2012 | 16/6/2026 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do… | |
| Modificada | Media (5.5) | 1.3% | — | Ark-web A-formArk-web A-form BambooArk-web A-form PCArk-web A-form PC Mobile | 3/11/2011 | 16/6/2026 | The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require administrative authentication, which allows remote authenticated users to modify data via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomlabamboo JB Simpla | 6/1/2010 | 16/6/2026 | SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php. NOTE: the vendor disputes this report, saying: "JoomlaBamboo has… |