Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
293 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.31% | — | Jirafeau | 4/7/2025 | 17/6/2026 | Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents could be exploited for cross site scripting. This was done by storing the MIME type of a file and allowing only browser preview for MIME types beginning with image (except for image/svg+xml, see… | |
| Analizada | Alta (7.2) | 0.69% | — | Atlassian Jira Data CenterAtlassian Jira Server | 20/5/2025 | 17/6/2026 | This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of… | |
| Aplazada | Alta (7.7) | 0.39% | — | Xwiki Jira ExtensionAI | 3/4/2025 | 17/6/2026 | The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, any logged in XWiki user could edit his/her user profile wiki page and use that JIRA macro, specifying a fake JIRA URL that returns an XML specifying a DOCTYPE pointing to… | |
| Analizada | Media (4.3) | 0.32% | — | Atlassian Jira Data CenterAtlassian Jira Server | 11/2/2025 | 17/6/2026 | An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account. | |
| Analizada | Media (6.1) | 0.24% | — | Jirafeau | 6/12/2024 | 17/6/2026 | Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be exploited for cross site scripting. This was done by storing the MIME type of a file and preventing the browser preview for MIME type image/svg+xml. This issue was first reported in CVE-2022-30110.… | |
| Modificada | Media (6.5) | 0.44% | — | Atlassian Jira Data CenterAtlassian Jira Server | 18/6/2024 | 17/6/2026 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 Jira Core Data Center… | |
| Modificada | Alta (8.8) | 88% | 💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence ServerAtlassian FisheyeAtlassian Crucible+3 | 21/5/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Microsoft Entra Jira SSO Plugin | 13/2/2024 | 10/8/2026 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Neuvector Vulnerability ScannerJenkins JiraJenkins Google Compute EngineJenkins Matlab | 29/11/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | |
| Modificada | Media (6.5) | 0.61% | — | Jenkins Jira | 29/11/2023 | 17/6/2026 | Jenkins Jira Plugin 3.11 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. | |
| Modificada | Media (4.1) | 0.43% | — | Discourse Jira | 6/10/2023 | 17/6/2026 | Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site setting. A moderator user could manipulate the… | |
| Modificada | Alta (8.8) | 0.26% | — | Icinga WEB Jira Integration | 5/7/2023 | 17/6/2026 | icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no… | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Crítica (9.1) | 16% | — | Atlassian Jira Service Management | 1/2/2023 | 17/6/2026 | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service… | |
| Modificada | Media (5.5) | 0.19% | — | Jenkins Jira Pipeline Steps | 26/1/2023 | 17/6/2026 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (5.5) | 0.20% | — | Jenkins Jira Pipeline Steps | 26/1/2023 | 17/6/2026 | Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 0.77% | — | Jenkins Jira Pipeline Steps | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.52% | — | Jenkins Jira Pipeline Steps | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Crítica (9.8) | 2.1% | — | Kujirahand Nadesiko3 | 5/12/2022 | 17/6/2026 | OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product. | |
| Modificada | Alta (7.5) | 1.6% | — | Kujirahand Nadesiko3 | 5/12/2022 | 17/6/2026 | Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to inject an invalid value to decodeURIComponent of nako3edit, which may lead the server to crash. | |
| Modificada | Crítica (9.8) | 2.1% | — | Kujirahand Nadesiko3 | 5/12/2022 | 17/6/2026 | OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product. | |
| Modificada | Alta (8.8) | 0.60% | — | Atlassian Jira Align | 14/10/2022 | 17/6/2026 | The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. | |
| Modificada | Media (4.9) | 0.91% | — | Atlassian Jira Align | 14/10/2022 | 17/6/2026 | The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP… | |
| Modificada | Media (5.3) | 0.51% | — | Netic User Export FOR Jira | 5/9/2022 | 17/6/2026 | The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint. | |
| Modificada | Media (6.1) | 66% | — | Atlassian Jira Data CenterAtlassian Jira Server | 10/8/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8. |