Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.67% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to create, view, and delete BitBucket Server consumers. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Bitbucket Server Integration | 29/3/2022 | 17/6/2026 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth consumers, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create BitBucket Server consumers. | |
| Modificada | Alta (7.1) | 0.66% | — | Jenkins Bitbucket Branch Source | 12/1/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Media (4.3) | 0.85% | — | Jenkins Bitbucket Branch Source | 12/1/2022 | 17/6/2026 | A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.8) | 0.27% | — | Atlassian Bitbucket | 18/2/2021 | 17/6/2026 | The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory. | |
| Modificada | Media (6.5) | 0.56% | — | Atlassian Bitbucket | 9/7/2020 | 17/6/2026 | Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack. | |
| Modificada | Media (4.3) | 0.83% | — | Atlassian Bitbucket | 9/7/2020 | 17/6/2026 | Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (8.8) | 2.5% | — | Atlassian Bitbucket | 15/1/2020 | 17/6/2026 | Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3,… | |
| Modificada | Alta (8.8) | 1.6% | — | Atlassian Bitbucket | 15/1/2020 | 17/6/2026 | Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from… | |
| Modificada | Alta (8.8) | 2.6% | — | Atlassian Bitbucket | 15/1/2020 | 17/6/2026 | Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version… | |
| Modificada | Media (4.3) | 1.3% | — | Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+4 | 8/11/2019 | 17/6/2026 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the… | |
| Modificada | Alta (7.8) | 0.33% | — | Jenkins Bitbucket Oauth | 23/10/2019 | 17/6/2026 | Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.8) | 7.8% | — | Atlassian Bitbucket | 19/9/2019 | 17/6/2026 | The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed… | |
| Modificada | Crítica (9.1) | 4.4% | — | Atlassian Bitbucket | 3/6/2019 | 17/6/2026 | Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14.4 (fixed version for 5.14.x), from 5.15.0 before 5.15.3 (fixed version for 5.15.x), from 5.16.0 before 5.16.3 (fixed version for 5.16.x), from 6.0.0 before 6.0.3 (fixed… | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Bitbucket Approve | 4/4/2019 | 17/6/2026 | Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Crítica (9.9) | 3.4% | — | Atlassian Bitbucket | 22/3/2018 | 17/6/2026 | In browser editing in Atlassian Bitbucket Server from version 4.13.0 before 5.4.8 (the fixed version for 4.13.0 through 5.4.7), 5.5.0 before 5.5.8 (the fixed version for 5.5.x), 5.6.0 before 5.6.5 (the fixed version for 5.6.x), 5.7.0 before 5.7.3 (the fixed version for 5.7.x), and 5.8.0 before 5.8.2 (the fixed version… | |
| Modificada | Media (4.3) | 0.99% | — | Atlassian Bitbucket | 15/2/2018 | 17/6/2026 | Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 before 5.5.6 (the fixed version for 5.5.x), from version 5.6.0 before 5.6.3 (the fixed version for 5.6.x), from version… | |
| Modificada | Alta (7.5) | 1.8% | — | Atlassian Bitbucket | 15/2/2018 | 17/6/2026 | The download commit resource in Atlassian Bitbucket Server from version 5.1.0 before version 5.1.7, from version 5.2.0 before version 5.2.5, from version 5.3.0 before version 5.3.3 and from version 5.4.0 before version 5.4.1 allows remote attackers to write files to disk potentially allowing them to gain code… | |
| Modificada | Media (5.3) | 1.4% | — | Atlassian Bitbucket | 2/2/2018 | 17/6/2026 | The repository settings resource in Atlassian Bitbucket Server before version 5.6.0 allows remote attackers to read the first line of arbitrary files via a path traversal vulnerability through the default branch name. | |
| Modificada | Media (6.5) | 1.3% | — | Atlassian Bitbucket | 2/2/2018 | 17/6/2026 | The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), from version 5.1.0 before 5.1.8 (the fixed version for 5.1.x), from version 5.2.0 before 5.2.6 (the fixed version for… | |
| Modificada | Media (4.3) | 0.88% | — | Atlassian Bitbucket | 2/2/2018 | 17/6/2026 | The Github repository importer in Atlassian Bitbucket Server before version 5.3.0 allows remote attackers to determine if a service they could not otherwise reach has open ports via a Server Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (8.5) | 0.59% | — | Atlassian Bitbucket Auto Unapprove Plugin | 5/12/2017 | 17/6/2026 | It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin, however since the auto-unapprove plugin is… | |
| Modificada | Media (4.3) | 1.8% | — | Atlassian Bitbucket | 10/4/2017 | 17/6/2026 | Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource. | |
| Modificada | Baja (2.1) | 0.43% | — | Bitbucket Xnbd | 13/2/2013 | 16/6/2026 | The redirect_stderr function in xnbd_common.c in xnbd-server and xndb-wrapper in xNBD 0.1.0 allow local users to overwrite arbitrary files via a symlink attack on /tmp/xnbd.log. |