Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.84% | — | Atlassian FisheyeAtlassian Crucible | 16/2/2018 | 17/6/2026 | The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup. | |
| Modificada | Media (6.1) | 0.85% | — | Atlassian Fisheye | 16/2/2018 | 17/6/2026 | Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author. | |
| Modificada | Alta (7.8) | 0.43% | — | Fishshell FishFedoraproject Fedora | 9/2/2018 | 17/6/2026 | fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER. | |
| Modificada | Media (4.3) | 0.79% | — | Atlassian FisheyeAtlassian Crucible | 2/2/2018 | 17/6/2026 | The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for… | |
| Modificada | Media (5.4) | 0.59% | — | Atlassian CrucibleAtlassian Fisheye | 2/2/2018 | 17/6/2026 | The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying… | |
| Modificada | Crítica (9.8) | 1.9% | — | Atlassian FisheyeAtlassian Crucible | 1/2/2018 | 17/6/2026 | It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fisheye or Crucible or who hosts a website that a user who can access the web interface of Fisheye or Crucible visits, is able to exploit this… | |
| Modificada | Alta (7.5) | 1.1% | — | Jolla Sailfish OS | 12/1/2018 | 17/6/2026 | Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL. | |
| Modificada | Crítica (9) | 2.3% | — | Atlassian CrucibleAtlassian Fisheye | 29/11/2017 | 17/6/2026 | Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software. | |
| Modificada | Media (5.4) | 1.2% | — | Oracle Glassfish Server | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical User Interface). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish… | |
| Modificada | Media (6.3) | 1.2% | — | Oracle Glassfish Server | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Alta (7.3) | 1.5% | — | Oracle Glassfish Server | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Media (6.3) | 1.2% | — | Oracle Glassfish Server | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Media (6.1) | 1.1% | — | Atlassian CrucibleAtlassian Fisheye | 11/10/2017 | 17/6/2026 | Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter. | |
| Modificada | Media (5.4) | 0.85% | — | Atlassian CrucibleAtlassian Fisheye | 11/10/2017 | 17/6/2026 | The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Atlassian CrucibleAtlassian Fisheye | 24/8/2017 | 17/6/2026 | The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system. | |
| Modificada | Alta (7.5) | 2.0% | — | Atlassian CrucibleAtlassian Fisheye | 24/8/2017 | 17/6/2026 | The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks. | |
| Modificada | Media (5.4) | 0.82% | — | Atlassian Fisheye | 24/8/2017 | 17/6/2026 | The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters. | |
| Modificada | Media (5.4) | 0.82% | — | Atlassian CrucibleAtlassian Fisheye | 24/8/2017 | 17/6/2026 | The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file. | |
| Modificada | Media (5.4) | 0.83% | — | Atlassian CrucibleAtlassian Fisheye | 24/8/2017 | 17/6/2026 | Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file. | |
| Modificada | Media (5.4) | 0.82% | — | Atlassian CrucibleAtlassian Fisheye | 24/8/2017 | 17/6/2026 | The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter. | |
| Analizada | Crítica (9.8) | 2.0% | — | Thermofisher Dt8x Firmware | 17/7/2017 | 17/6/2026 | dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data. | |
| Modificada | Crítica (9.8) | 1.7% | — | Oracle Glassfish Server | 17/7/2017 | 17/6/2026 | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of administrative user and grant access to the web-based administration interface. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Oracle Glassfish Server | 17/7/2017 | 17/6/2026 | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication. | |
| Modificada | Alta (7.5) | 99% | 💥 Exploit | Oracle Glassfish Server | 17/7/2017 | 17/6/2026 | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request. | |
| Analizada | Crítica (9.8) | 64% | 💥 Exploit | Thermofisher Dt80 DEX Firmware | 12/7/2017 | 17/6/2026 | dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI. |