Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.3% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another… | |
| Modificada | Alta (8.1) | 1.4% | — | Atlassian Crowd | 29/3/2019 | 17/6/2026 | The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability. | |
| Modificada | Media (5.3) | 1.9% | — | Advance Crowdfunding Script Project Advance Crowdfunding Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Advance Crowdfunding Script 2.0.3 has directory traversal via a direct request for a listing of an uploads directory such as the wp-content/uploads/2018/12 directory. | |
| Modificada | Alta (8.1) | 1.5% | — | Atlassian Crowd | 13/2/2019 | 17/6/2026 | Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability. | |
| Modificada | Media (4.9) | 1.1% | — | Atlassian Crowd | 29/1/2019 | 17/6/2026 | Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources. | |
| Modificada | Alta (7.8) | 0.31% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2. | |
| Modificada | Media (6.5) | 0.77% | — | Atlassian Crowd2 | 9/1/2019 | 17/6/2026 | An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings. | |
| Modificada | Alta (7.5) | 1.1% | — | Crowdnext Project Crowdnext | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Hyipcrowdsale1 Project Hyipcrowdsale1 | 9/7/2018 | 17/6/2026 | The mint function of a smart contract implementation for HYIPCrowdsale1, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.0% | — | Crowdnext Project Crowdnext | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for Crowdnext (CNX), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Media (6.8) | 0.57% | — | Atlassian Crowd | 31/1/2018 | 17/6/2026 | The 'crowd-application' plugin module (notably used by the Google Apps plugin) in Atlassian Crowd from version 1.5.0 before version 3.1.2 allowed an attacker to impersonate a Crowd user in REST requests by being able to authenticate to a directory bound to an application using the feature. Given the following… | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Realestate Crowdfunding Script Project Realestate Crowdfunding Script | 13/12/2017 | 17/6/2026 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Crowdfunding Script Project Crowdfunding Script | 13/12/2017 | 17/6/2026 | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. | |
| Modificada | Alta (7.5) | 0.60% | — | Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+10 | 22/11/2017 | 17/6/2026 | Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and… | |
| Modificada | Crítica (9.8) | 4.7% | — | Atlassian Crowd | 9/12/2016 | 17/6/2026 | The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. | |
| Modificada | Alta (7.5) | 1.9% | — | Atlassian Crowd | 1/7/2013 | 16/6/2026 | Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 20130704, the vendor could not reproduce the issue, stating "We've been unable to substantiate the existence of [CVE-2013-3926]. The author of the article has not contacted… | |
| Modificada | Media (5.8) | 1.8% | — | Atlassian Crowd | 1/7/2013 | 16/6/2026 | Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference. | |
| Modificada | Crítica (9.1) | 66% | 💥 Exploit | Atlassian BambooAtlassian ConfluenceAtlassian Confluence ServerAtlassian Crowd+3 | 22/5/2012 | 16/6/2026 | Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do… |