Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.68% | — | Atlassian Jira Server | 23/8/2019 | 17/6/2026 | The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (5.3) | 18% | 💥 Exploit | Atlassian Jira Server | 23/8/2019 | 17/6/2026 | The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check. | |
| Modificada | Media (5.3) | 2.7% | — | Atlassian Jira Server | 23/8/2019 | 17/6/2026 | Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing permissions check. | |
| Modificada | Media (5.4) | 0.92% | — | Atlassian Jira Server | 23/8/2019 | 17/6/2026 | The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in image attribute specification. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Jira Server | 23/8/2019 | 17/6/2026 | The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability. | |
| Modificada | Media (4.3) | 0.79% | — | Atlassian JiraAtlassian Jira Server | 23/8/2019 | 17/6/2026 | The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (6.5) | 0.80% | — | Atlassian JiraAtlassian Jira Server | 23/8/2019 | 17/6/2026 | Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF). | |
| Modificada | Media (4.3) | 0.65% | — | Atlassian JiraAtlassian Jira Server | 23/8/2019 | 17/6/2026 | The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (6.1) | 1.2% | — | Atlassian JiraAtlassian Jira Server | 23/8/2019 | 17/6/2026 | The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect. | |
| Modificada | Media (5.3) | 1.8% | — | Atlassian Jira Server | 13/8/2019 | 17/6/2026 | The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via an information disclosure vulnerability. | |
| Analizada | Crítica (9.8) | 85% | ⚠ Explotación activa💥 Exploit | Atlassian Jira Server | 9/8/2019 | 17/6/2026 | There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0… | |
| Modificada | Alta (8.1) | 2.6% | — | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass… | |
| Modificada | Alta (7.5) | 60% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check. | |
| Modificada | Media (5.3) | 53% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | |
| Modificada | Media (6.1) | 8.9% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter. | |
| Modificada | Media (5.3) | 13% | 💥 Exploit | Atlassian JiraAtlassian Jira Server | 22/5/2019 | 17/6/2026 | The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian Jira Server | 3/5/2019 | 17/6/2026 | The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jql parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Atlassian JiraAtlassian Jira Server | 30/4/2019 | 17/6/2026 | The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check. | |
| Modificada | Media (5.4) | 3.3% | — | Atlassian Application LinksAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian Crowd+4 | 30/4/2019 | 17/6/2026 | Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl… | |
| Modificada | Media (5.4) | 0.91% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the… | |
| Modificada | Media (4.1) | 1.1% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before… | |
| Modificada | Media (5.4) | 0.94% | — | Atlassian JiraAtlassian Jira Server | 13/2/2019 | 17/6/2026 | The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when… | |
| Modificada | Media (6.1) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before… | |
| Modificada | Media (6.1) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version… | |
| Modificada | Media (4.7) | 1.4% | — | Atlassian JiraAtlassian Jira Server | 23/10/2018 | 17/6/2026 | Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version… |