Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.79% | — | Atlassian Assets Discovery Data Center | 20/2/2024 | 17/6/2026 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects… | |
| Analizada | Alta (8.5) | 0.47% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 20/2/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to… | |
| Modificada | Alta (7.8) | 0.39% | — | Atlassian Sourcetree | 16/1/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.15 | |
| Modificada | Alta (7.5) | 15% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services… | |
| Modificada | Alta (7.5) | 1.8% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets… | |
| Modificada | Alta (8.8) | 1.5% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in… | |
| Modificada | Alta (8.8) | 1.4% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by… | |
| Modificada | Alta (8.8) | 1.6% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Crítica (9.8) | 25% | 💥 PoC | Atlassian Companion | 6/12/2023 | 17/6/2026 | Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code. | |
| Modificada | Alta (8.8) | 11% | — | Atlassian Assets Discovery CloudAtlassian Assets Discovery Data CenterAtlassian Assets Discovery Data Server | 6/12/2023 | 17/6/2026 | This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent. | |
| Modificada | Alta (8.8) | 13% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 6/12/2023 | 17/6/2026 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server… | |
| Modificada | Media (5.4) | 0.57% | — | Weather-atlas Weather Atlas | 22/11/2023 | 17/6/2026 | The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas' shortcode in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 1.2% | — | Atlassian Crowd | 21/11/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.0, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 1.2% | — | Atlassian Bamboo | 21/11/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high… | |
| Modificada | Alta (7.5) | 0.60% | — | Mongodb Atlas Kubernetes Operator | 7/11/2023 | 17/6/2026 | The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets while DEBUG mode logging is enabled. This issue affects MongoDB Atlas Kubernetes Operator versions: 1.5.0, 1.6.0, 1.6.1, 1.7.0. Please note that this is reported on an… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence Server | 31/10/2023 | 17/6/2026 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence Server | 4/10/2023 | 17/6/2026 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.… | |
| Modificada | Alta (8.8) | 15% | — | Atlassian Bitbucket Data CenterAtlassian Bitbucket Server | 19/9/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Atlas | 19/7/2023 | 17/6/2026 | A vulnerability was found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic. Affected by this issue is some unknown functionality of the file /home/search. The manipulation of the argument search_string leads to cross site scripting. The attack may be launched remotely. The identifier… | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Atlas | 19/7/2023 | 17/6/2026 | A vulnerability has been found in Creativeitem Atlas Business Directory Listing 2.13 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /home/filter_listings. The manipulation of the argument price-range leads to cross site scripting. The attack can be launched… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Bamboo Data CenterAtlassian Bamboo Server | 19/7/2023 | 17/6/2026 | This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call… | |
| Modificada | Alta (8.8) | 2.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to… |