Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Rainbowfishsoftware Pacsone Server3/2/202117/6/2026
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges.
ModificadaMedia (6.1)6.2%💥 ExploitRainbowfishsoftware Pacsone Server3/2/202117/6/2026
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
ModificadaAlta (8.8)1.1%—Rainbowfishsoftware Pacsone Server3/2/202117/6/2026
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection.
ModificadaMedia (4.3)0.87%—Atlassian CrucibleAtlassian Fisheye2/2/202117/6/2026
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4.
ModificadaMedia (5.3)1.2%—Atlassian CrucibleAtlassian Fisheye18/1/202117/6/2026
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5.
ModificadaAlta (7.5)1.2%—Atlassian CrucibleAtlassian Fisheye25/11/202017/6/2026
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
ModificadaAlta (7.5)1.2%—Atlassian CrucibleAtlassian Fisheye25/11/202017/6/2026
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.
ModificadaCrítica (9.1)1.3%—Mapfish Print2/10/202017/6/2026
In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.
ModificadaMedia (6.1)0.80%—Mapfish Print2/10/202017/6/2026
In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting.
ModificadaCrítica (9.8)1.6%—Rainbowfishsoftware Pacsone Server30/9/202017/6/2026
RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.
ModificadaMedia (5.4)0.55%—Rainbowfishsoftware Pacsone Server30/9/202017/6/2026
RainbowFish PacsOne Server 6.8.4 allows XSS.
ModificadaAlta (8.8)1.2%—Rainbowfishsoftware Pacsone Server30/9/202017/6/2026
RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control.
ModificadaMedia (6.1)0.64%—Hack Hfish30/9/202017/6/2026
An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information.
ModificadaMedia (6.5)1.0%—Atlassian Fisheye5/8/202017/6/2026
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
ModificadaMedia (5.4)0.77%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
ModificadaAlta (8.8)0.57%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.
ModificadaMedia (5.3)1.2%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability.
ModificadaMedia (5.3)1.2%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability.
ModificadaMedia (4.3)0.96%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability.
ModificadaMedia (4.3)0.77%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability.
ModificadaMedia (5.4)0.63%—Atlassian CrucibleAtlassian Fisheye1/6/202017/6/2026
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.
ModificadaAlta (7)0.29%—Fishshell Fish28/1/202017/6/2026
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
ModificadaCrítica (9.8)3.2%—Fishshell Fish28/1/202017/6/2026
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.
ModificadaAlta (7)0.31%—Fishshell Fish28/1/202017/6/2026
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.
ModificadaMedia (4.3)0.73%—Atlassian CrucibleAtlassian Fisheye11/12/201917/6/2026
The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability.