Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.63%—Atlassian Jira Service Management3/8/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.
ModificadaAlta (7.2)45%—Atlassian Jira Data CenterAtlassian Jira Server1/8/202217/6/2026
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to…
ModificadaMedia (5.7)0.70%—Atlassian Jira Service DeskAtlassian Jira Service Management26/7/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this…
ModificadaAlta (8.8)2.4%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource…
ModificadaCrítica (9.8)5.5%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.…
ModificadaMedia (5.4)0.59%—Appfire Jira Misc Custom Fields7/7/202217/6/2026
The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add Auto Indexing Rule function.
ModificadaMedia (6.5)72%💥 PoCAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service DeskAtlassian Jira Service Management30/6/202217/6/2026
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version…
ModificadaMedia (6.1)0.61%—Jirafeau17/5/202217/6/2026
The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could upload image/svg+xml files containing JavaScript. When someone visits the File Preview URL for this file, the JavaScript inside of this image/svg+xml file will be executed in…
ModificadaCrítica (9.8)88%💥 ExploitAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service Management20/4/202217/6/2026
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also…
ModificadaMedia (5.4)0.85%—Jenkins Jira12/4/202217/6/2026
Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Release Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (4.3)0.74%—Jenkins Jiratestresultreporter29/3/202217/6/2026
A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaAlta (8.8)0.72%—Jenkins Jiratestresultreporter29/3/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
ModificadaAlta (7.2)2.3%—Atlassian Jira Data CenterAtlassian Jira Server8/3/202217/6/2026
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to…
ModificadaMedia (4.8)0.57%—Atlassian Data CenterAtlassian Jira28/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
ModificadaMedia (4.8)0.43%—Atlassian Jira Service Management24/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are…
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
ModificadaMedia (6.5)0.62%—Atlassian Jira Data CenterAtlassian Jira Server15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15,…
ModificadaMedia (4.3)0.48%—Atlassian Data CenterAtlassian Jira15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16,…
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.41%—Atlassian Jira Data CenterAtlassian Jira Server15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
ModificadaMedia (4.3)0.81%—Atlassian Jira Service Management10/1/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.81%—Atlassian Jira Service Management10/1/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
ModificadaAlta (7.2)4.1%—Atlassian Data CenterAtlassian JiraAtlassian Jira Data CenterAtlassian Jira Server6/1/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected…
ModificadaMedia (6.5)1.1%—Atlassian Jira Data CenterAtlassian Jira Server5/1/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions via a Broken Access Control vulnerability in the /secure/EditSubscription.jspa endpoint. The affected versions are before version 8.13.21, and from version 8.14.0 before…
ModificadaMedia (6.1)55%—Atlassian Jira ServerAtlassian Jira Server AND Data Center4/1/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (XSS) vulnerability in the /rest/collectors/1.0/template/custom endpoint. To exploit this issue, the attacker must trick a user into visiting a malicious…