Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Rainbowfishsoftware Pacsone Server | 3/2/2021 | 17/6/2026 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by incorrect access control, which can result in remotely gaining administrator privileges. | |
| Modificada | Media (6.1) | 6.2% | 💥 Exploit | Rainbowfishsoftware Pacsone Server | 3/2/2021 | 17/6/2026 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS). | |
| Modificada | Alta (8.8) | 1.1% | — | Rainbowfishsoftware Pacsone Server | 3/2/2021 | 17/6/2026 | PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by SQL injection. | |
| Modificada | Media (4.3) | 0.87% | — | Atlassian CrucibleAtlassian Fisheye | 2/2/2021 | 17/6/2026 | Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. The affected versions are before version 4.8.4. | |
| Modificada | Media (5.3) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 18/1/2021 | 17/6/2026 | Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory. The affected versions are before version 4.8.5. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 25/11/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4. | |
| Modificada | Alta (7.5) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 25/11/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4. | |
| Modificada | Crítica (9.1) | 1.3% | — | Mapfish Print | 2/10/2020 | 17/6/2026 | In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style. | |
| Modificada | Media (6.1) | 0.80% | — | Mapfish Print | 2/10/2020 | 17/6/2026 | In mapfish-print before version 3.24, a user can use the JSONP support to do a Cross-site scripting. | |
| Modificada | Crítica (9.8) | 1.6% | — | Rainbowfishsoftware Pacsone Server | 30/9/2020 | 17/6/2026 | RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page. | |
| Modificada | Media (5.4) | 0.55% | — | Rainbowfishsoftware Pacsone Server | 30/9/2020 | 17/6/2026 | RainbowFish PacsOne Server 6.8.4 allows XSS. | |
| Modificada | Alta (8.8) | 1.2% | — | Rainbowfishsoftware Pacsone Server | 30/9/2020 | 17/6/2026 | RainbowFish PacsOne Server 6.8.4 has Incorrect Access Control. | |
| Modificada | Media (6.1) | 0.64% | — | Hack Hfish | 30/9/2020 | 17/6/2026 | An issue was discovered in HFish 0.5.1. When a payload is inserted where the password is entered, XSS code is triggered when the administrator views the information. | |
| Modificada | Media (6.5) | 1.0% | — | Atlassian Fisheye | 5/8/2020 | 17/6/2026 | Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3. | |
| Modificada | Media (5.4) | 0.77% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter. | |
| Modificada | Alta (8.8) | 0.57% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (5.3) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The /rest/jira-ril/1.0/jira-rest/applinks resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get information about any configured Jira application links via an information disclosure vulnerability. | |
| Modificada | Media (5.3) | 1.2% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The /plugins/servlet/jira-blockers/ resource in the crucible-jira-ril plugin in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to get the ID of configured Jira application links via an information disclosure vulnerability. | |
| Modificada | Media (4.3) | 0.96% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The /json/fe/activeUserFinder.do resource in Altassian Fisheye and Crucible before version 4.8.1 allows remote attackers to view user user email addresses via a information disclosure vulnerability. | |
| Modificada | Media (4.3) | 0.77% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The /profile/deleteWatch.do resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to remove another user's watching settings for a repository via an improper authorization vulnerability. | |
| Modificada | Media (5.4) | 0.63% | — | Atlassian CrucibleAtlassian Fisheye | 1/6/2020 | 17/6/2026 | The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives. | |
| Modificada | Alta (7) | 0.29% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name. | |
| Modificada | Crítica (9.8) | 3.2% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt. | |
| Modificada | Alta (7) | 0.31% | — | Fishshell Fish | 28/1/2020 | 17/6/2026 | The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name. | |
| Modificada | Media (4.3) | 0.73% | — | Atlassian CrucibleAtlassian Fisheye | 11/12/2019 | 17/6/2026 | The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attackers to remove another user's favourite setting for a project via an improper authorization vulnerability. |