Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.31% | — | Atlassian Agiloft | 26/8/2025 | 17/6/2026 | Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows 'import/export', allowing an authenticated attacker to import the template file and perform path traversal on the local system files. Users should upgrade to Agiloft Release 31. | |
| Analizada | Crítica (9.1) | 0.43% | — | Craws Openatlas | 4/8/2025 | 17/6/2026 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability. | |
| Analizada | Alta (8.1) | 0.39% | — | Craws Openatlas | 4/8/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field. | |
| Analizada | Crítica (9.8) | 0.53% | — | Craws Openatlas | 4/8/2025 | 17/6/2026 | Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password. | |
| Aplazada | Crítica (9.8) | 0.46% | — | RevelacodeAIMongodb AtlasAI | 28/7/2025 | 17/6/2026 | RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to… | |
| Analizada | Media (5.9) | 0.13% | — | Atlassian Sourcetree | 24/7/2025 | 17/6/2026 | This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact… | |
| Analizada | Alta (7.2) | 0.69% | — | Atlassian Jira Data CenterAtlassian Jira Server | 20/5/2025 | 17/6/2026 | This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server 5.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Service Management Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of… | |
| Analizada | Alta (7.1) | 0.57% | — | Apache Atlas | 13/2/2025 | 17/6/2026 | An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue. | |
| Analizada | Media (4.3) | 0.32% | — | Atlassian Jira Data CenterAtlassian Jira Server | 11/2/2025 | 17/6/2026 | An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account. | |
| Analizada | Media (6.4) | 0.20% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 27/11/2024 | 17/6/2026 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about… | |
| Aplazada | Alta (7.1) | 0.27% | — | Weather-atlas Weather Atlas WidgetAI | 20/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weather Atlas Widget weather-atlas allows Reflected XSS.This issue affects Weather Atlas Widget: from n/a through <= 3.0.3. | |
| Analizada | Alta (8.8) | 0.74% | — | Atlassian Sourcetree | 19/11/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 4.2.8 of Sourcetree for Mac and 3.4.19 for Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to execute arbitrary code which has high impact to… | |
| Aplazada | Media (5.9) | 0.27% | — | Search Atlas Group Search Atlas SEOAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Search Atlas Group Search Atlas SEO metasync allows Stored XSS.This issue affects Search Atlas SEO: from n/a through <= 1.8.2. | |
| Analizada | Alta (8.2) | 0.76% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 21/8/2024 | 17/6/2026 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. * Confluence Data Center and Server 7.19: Upgrade to a release greater than or… | |
| Modificada | Alta (8) | 2.7% | 💥 PoC | Atlassian Bamboo | 20/8/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code… | |
| Aplazada | Media (6.5) | 0.24% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent cross-site request forgery (CSRF) attacks where a resource owner might have their session associated with protected resources belonging to an attacker. When this project is… | |
| Aplazada | Media (6.5) | 0.25% | — | Atlassian OauthAI | 15/8/2024 | 17/6/2026 | In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, associating the user's session with the attacker's protected resources. While… | |
| Analizada | Media (4.3) | 0.25% | — | Atlassian Bitbucket Data Center | 24/7/2024 | 17/6/2026 | There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3.1 and a CVSS Vector… | |
| Modificada | Media (5.4) | 0.32% | — | Atlaspolicy Power BI Embedded | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atlas Public Policy Power BI Embedded for WordPress allows Stored XSS.This issue affects Power BI Embedded for WordPress: from n/a through 1.1.7. | |
| Modificada | Alta (8.1) | 0.75% | — | Atlassian Bamboo | 16/7/2024 | 17/6/2026 | This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file,… | |
| Modificada | Alta (8.7) | 0.89% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/7/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high… | |
| Modificada | Media (6.5) | 0.44% | — | Atlassian Jira Data CenterAtlassian Jira Server | 18/6/2024 | 17/6/2026 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Core Data Center. Jira Core Data Center 9.4: Upgrade to a release greater than or equal to 9.4.21 Jira Core Data Center 9.12: Upgrade to a release greater than or equal to 9.12.8 Jira Core Data Center… | |
| Modificada | Alta (8.8) | 88% | 💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence ServerAtlassian FisheyeAtlassian Crucible+3 | 21/5/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 0.93% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 19/3/2024 | 17/6/2026 | This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high… | |
| Modificada | Alta (8.8) | 0.23% | — | Atlasgondal Export ALL Urls | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Atlas Gondal Export Media URLs.This issue affects Export Media URLs: from n/a through 1.0. |