Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
386 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.20% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 27/11/2024 | 17/6/2026 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about… | |
| Analizada | Media (6.3) | 0.43% | — | Cisco Prime Data Center Network Manager | 18/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. The vulnerability is due to a failure to limit access to resources that are intended for users with… | |
| Analizada | Alta (8.1) | 0.51% | — | Cisco Data Center Network Manager | 18/11/2024 | 17/6/2026 | A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient path restriction enforcement. An attacker could exploit this… | |
| Aplazada | Alta (7.2) | 0.46% | — | Schneider-electric Data Center ExpertAI | 11/10/2024 | 17/6/2026 | CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root. | |
| Analizada | Alta (8.2) | 0.76% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 21/8/2024 | 17/6/2026 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. * Confluence Data Center and Server 7.19: Upgrade to a release greater than or… | |
| Analizada | Media (6.8) | 0.16% | — | Intel Data Center GPU MAX 1100 FirmwareIntel Data Center GPU MAX 1550 Firmware | 14/8/2024 | 17/6/2026 | Improper conditions check in some Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Media (4.3) | 0.25% | — | Atlassian Bitbucket Data Center | 24/7/2024 | 17/6/2026 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector… | |
| Modificada | Alta (8.7) | 0.89% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/7/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high… | |
| Modificada | Media (6.5) | 0.44% | — | Atlassian Jira Data CenterAtlassian Jira Server | 18/6/2024 | 17/6/2026 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 Jira Core Data Center… | |
| Modificada | Alta (8.8) | 88% | — | Atlassian Confluence Data CenterAtlassian Confluence ServerAtlassian FisheyeAtlassian Crucible+3 | 21/5/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Aplazada | Media (6) | 0.22% | — | Intel Data Center GPU MAX Series 1100AIIntel Data Center GPU MAX Series 1550AI | 16/5/2024 | 17/6/2026 | Improper conditions check in the Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow an privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.8) | 0.93% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 19/3/2024 | 17/6/2026 | This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high… | |
| Analizada | Alta (7.2) | 0.79% | — | Atlassian Assets Discovery Data Center | 20/2/2024 | 17/6/2026 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects… | |
| Analizada | Alta (8.5) | 0.47% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 20/2/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to… | |
| Modificada | Alta (8.8) | 1.7% | — | Broadcom Symantec Data Center Security Server | 26/1/2024 | 17/6/2026 | A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open a crafted document to achieve code execution. | |
| Modificada | Alta (7.5) | 15% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services… | |
| Modificada | Alta (7.5) | 1.8% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets… | |
| Modificada | Alta (8.8) | 1.5% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in… | |
| Modificada | Alta (8.8) | 1.4% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by… | |
| Modificada | Alta (8.8) | 1.6% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 11% | — | Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server | 6/12/2023 | 17/6/2026 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. | |
| Modificada | Alta (8.8) | 13% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 6/12/2023 | 17/6/2026 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server… | |
| Modificada | Crítica (9.8) | 0.73% | — | Intel Data Center Manager | 14/11/2023 | 17/6/2026 | Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Atlassian Confluence Data CenterAtlassian Confluence Server | 31/10/2023 | 17/6/2026 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative… |