Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items. | |
| Modificada | Media (5.3) | 0.18% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission. | |
| Analizada | Media (5.3) | 0.19% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users. | |
| Analizada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action. | |
| Analizada | Media (5.3) | 0.18% | — | Atlassian Jira Align | 22/10/2025 | 17/6/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level. | |
| Modificada | Media (5.3) | 0.21% | — | Atlassian Jira Align | 22/10/2025 | 30/9/2026 | Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist. | |
| Analizada | Alta (8.7) | 0.50% | — | Atlassian Jira Data CenterAtlassian Jira Server | 22/10/2025 | 17/6/2026 | This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by… | |
| Analizada | Alta (8.3) | 0.51% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 21/10/2025 | 30/9/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a… | |
| Aplazada | Media (6.5) | 0.28% | — | Search Atlas Group Search Atlas SEOAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Search Atlas Group Search Atlas SEO metasync allows Stored XSS.This issue affects Search Atlas SEO: from n/a through <= 2.5.4. | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Media (5.1) | 0.22% | — | Craws Openatlas | 29/8/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in OpenAtlas v8.9.0 from the Austrian Centre for Digital Humanities and Cultural Heritage (ACDH-CH), due to inadequate validation of user input when a POST request is sent. The vulnerabilities could allow a remote user to send specially crafted queries to an authenticated user… | |
| Analizada | Crítica (9.2) | 0.24% | — | Atlassian Agiloft | 26/8/2025 | 17/6/2026 | Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30. | |
| Analizada | Alta (8.7) | 0.34% | — | Atlassian Agiloft | 26/8/2025 | 17/6/2026 | Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30. | |
| Analizada | Media (4.8) | 0.43% | — | Atlassian Agiloft | 26/8/2025 | 17/6/2026 | Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine, allowing an authenticated attacker to achieve remote code execution by loading a specially crafted payload. Users should upgrade to Agiloft Release 31. |