Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Atlasgondal Export ALL Urls | 10/7/2023 | 17/6/2026 | The Export All URLs WordPress plugin before 4.6 does not sanitise and escape a parameter before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.34% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server is not a secure connection by default, which could allow an attacker to gain sensitive information by monitoring network traffic between user and controller. | |
| Modificada | Alta (7.5) | 0.56% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session. | |
| Modificada | Alta (7.5) | 0.34% | — | Atlascopco Power Focus 6000 Firmware | 12/6/2023 | 17/6/2026 | Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller. | |
| Modificada | Media (6.5) | 0.75% | — | Atlassian Confluence Server | 25/5/2023 | 17/6/2026 | Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature. | |
| Modificada | Media (5.4) | 0.38% | — | Atlasgondal Export ALL Urls | 10/5/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions. | |
| Modificada | Media (5.3) | 0.79% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 1/5/2023 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder… | |
| Modificada | Alta (7.4) | 0.22% | — | Palantir Atlasdb | 16/2/2023 | 17/6/2026 | It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API. A malicious attacker in a privileged network position could abuse this to perform a man-in-the-middle attack. A successful man-in-the-middle attack would allow them to… | |
| Modificada | Crítica (9.1) | 16% | — | Atlassian Jira Service Management | 1/2/2023 | 17/6/2026 | An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service… | |
| Modificada | Alta (8.8) | 1.4% | — | Apache Atlas | 14/12/2022 | 17/6/2026 | A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. | |
| Modificada | Crítica (9.8) | 0.95% | — | Atlassian Crowd | 17/11/2022 | 17/6/2026 | Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application… | |
| Modificada | Crítica (9.8) | 98% | 💥 Exploit | Atlassian Bitbucket | 17/11/2022 | 17/6/2026 | There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance… | |
| Modificada | Alta (7.5) | 0.86% | — | Atlassian Confluence Data Center | 15/11/2022 | 17/6/2026 | In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system. | |
| Modificada | Alta (7.5) | 1.0% | — | Atlassian Confluence Data Center | 15/11/2022 | 17/6/2026 | The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be downloaded. | |
| Modificada | Alta (8.8) | 0.60% | — | Atlassian Jira Align | 14/10/2022 | 17/6/2026 | The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox. | |
| Modificada | Media (4.9) | 0.91% | — | Atlassian Jira Align | 14/10/2022 | 17/6/2026 | The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP… | |
| Modificada | Media (6.5) | 1.2% | — | Atlasgondal Export ALL Urls | 29/8/2022 | 17/6/2026 | The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which is supposed to be the CSV file. This could allow high privilege users to delete arbitrary file from the server | |
| Analizada | Alta (8.8) | 99% | ⚠ Explotación activa💥 Exploit | Atlassian Bitbucket | 25/8/2022 | 17/6/2026 | Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from… | |
| Modificada | Media (6.1) | 66% | — | Atlassian Jira Data CenterAtlassian Jira Server | 10/8/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8. | |
| Modificada | Media (4.3) | 0.63% | — | Atlassian Jira Service Management | 3/8/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2. | |
| Modificada | Alta (7.2) | 45% | — | Atlassian Jira Data CenterAtlassian Jira Server | 1/8/2022 | 17/6/2026 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to… | |
| Modificada | Media (5.7) | 0.70% | — | Atlassian Jira Service DeskAtlassian Jira Service Management | 26/7/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this… | |
| Modificada | Media (5.4) | 0.68% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 26/7/2022 | 17/6/2026 | The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page… | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Atlassian Questions FOR Confluence | 20/7/2022 | 17/6/2026 | The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into… | |
| Modificada | Alta (8.8) | 2.4% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource… |