Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.7%—Atlassian ConfluenceAtlassian Confluence Server25/3/201917/6/2026
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from…
ModificadaMedia (6.5)1.7%—Atlassian Confluence Data CenterAtlassian Confluence Server13/2/201917/6/2026
Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.
ModificadaMedia (6.5)0.84%—Atlassian Questions FOR Confluence15/8/201817/6/2026
The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
ModificadaMedia (6.5)0.80%—Atlassian Questions FOR Confluence15/8/201817/6/2026
The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed version in Confluence version 6.9.0, allows remote attackers to modify a comment into an answer via a Cross-site request forgery (CSRF) vulnerability.
ModificadaMedia (4.3)0.64%—Jenkins Confluence Publisher1/8/201817/6/2026
A server-side request forgery vulnerability exists in Jenkins Confluence Publisher Plugin 2.0.1 and earlier in ConfluenceSite.java that allows attackers to have Jenkins submit login requests to an attacker-specified Confluence server URL with attacker specified credentials.
ModificadaMedia (4.7)1.00%—Atlassian Confluence10/7/201817/6/2026
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml.
ModificadaMedia (6.1)0.81%—Atlassian Confluence2/2/201817/6/2026
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter.
ModificadaMedia (6.1)0.81%—Atlassian Confluence2/2/201817/6/2026
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter.
ModificadaMedia (4.8)0.60%—Atlassian Confluence2/2/201817/6/2026
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro.
ModificadaMedia (5.4)0.58%—Atlassian Confluence2/2/201817/6/2026
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file.
ModificadaMedia (6.1)0.81%—Atlassian Confluence5/12/201717/6/2026
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme.
ModificadaMedia (4.3)1.3%—Atlassian Confluence15/6/201717/6/2026
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after…
ModificadaAlta (7.5)4.4%—Atlassian Confluence Server27/4/201717/6/2026
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
ModificadaMedia (5.4)0.71%—Atlassian Confluence10/4/201717/6/2026
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
ModificadaAlta (7.5)3.7%—Atlassian Confluence ServerAtlassian Jira Integration FOR Hipchat23/1/201717/6/2026
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by…
ModificadaMedia (6.1)3.2%💥 ExploitAtlassian Confluence18/1/201717/6/2026
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action.
ModificadaMedia (4.3)60%💥 ExploitAtlassian Confluence11/4/201617/6/2026
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action.
ModificadaMedia (6.1)2.1%💥 ExploitAtlassian Confluence11/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check.
ModificadaMedia (6.8)1.7%—Atlassian Confluence Server13/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication of administrators for requests that logout the user via a comment.
ModificadaMedia (6.4)3.0%—Atlassian JiraGliffyAtlassian Confluence Server22/5/201216/6/2026
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors.
ModificadaCrítica (9.1)66%💥 ExploitAtlassian BambooAtlassian ConfluenceAtlassian Confluence ServerAtlassian Crowd+322/5/201216/6/2026
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do…
ModificadaMedia (4.3)1.2%—Atlassian Confluence3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the dosearchsite.action module in Atlassian Confluence 2.0.1 Build 321 allows remote attackers to inject arbitrary web script or HTML via the searchQuery.queryString search module parameter.