Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.84%—Atlassian FisheyeAtlassian Crucible16/2/201817/6/2026
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the filename of a backup.
ModificadaMedia (6.1)0.85%—Atlassian Fisheye16/2/201817/6/2026
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a commit author.
ModificadaAlta (7.8)0.43%—Fishshell FishFedoraproject Fedora9/2/201817/6/2026
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
ModificadaMedia (4.3)0.79%—Atlassian FisheyeAtlassian Crucible2/2/201817/6/2026
The /rest/review-coverage-chart/1.0/data/<repository_name>/.json resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 was missing a permissions check, this allows remote attackers who do not have access to a particular repository to determine its existence and access review coverage statistics for…
ModificadaMedia (5.4)0.59%—Atlassian CrucibleAtlassian Fisheye2/2/201817/6/2026
The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying…
ModificadaCrítica (9.8)1.9%—Atlassian FisheyeAtlassian Crucible1/2/201817/6/2026
It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to occur. An attacker who can access the web interface of Fisheye or Crucible or who hosts a website that a user who can access the web interface of Fisheye or Crucible visits, is able to exploit this…
ModificadaAlta (7.5)1.1%—Jolla Sailfish OS12/1/201817/6/2026
Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.
ModificadaCrítica (9)2.3%—Atlassian CrucibleAtlassian Fisheye29/11/201717/6/2026
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.
ModificadaMedia (5.4)1.2%—Oracle Glassfish Server19/10/201717/6/2026
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration Graphical User Interface). The supported version that is affected is 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish…
ModificadaMedia (6.3)1.2%—Oracle Glassfish Server19/10/201717/6/2026
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful…
ModificadaAlta (7.3)1.5%—Oracle Glassfish Server19/10/201717/6/2026
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful…
ModificadaMedia (6.3)1.2%—Oracle Glassfish Server19/10/201717/6/2026
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful…
ModificadaMedia (6.1)1.1%—Atlassian CrucibleAtlassian Fisheye11/10/201717/6/2026
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.
ModificadaMedia (5.4)0.85%—Atlassian CrucibleAtlassian Fisheye11/10/201717/6/2026
The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.
ModificadaAlta (7.5)3.2%—Atlassian CrucibleAtlassian Fisheye24/8/201717/6/2026
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.
ModificadaAlta (7.5)2.0%—Atlassian CrucibleAtlassian Fisheye24/8/201717/6/2026
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.
ModificadaMedia (5.4)0.82%—Atlassian Fisheye24/8/201717/6/2026
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.
ModificadaMedia (5.4)0.82%—Atlassian CrucibleAtlassian Fisheye24/8/201717/6/2026
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.
ModificadaMedia (5.4)0.83%—Atlassian CrucibleAtlassian Fisheye24/8/201717/6/2026
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.
ModificadaMedia (5.4)0.82%—Atlassian CrucibleAtlassian Fisheye24/8/201717/6/2026
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.
AnalizadaCrítica (9.8)2.0%—Thermofisher Dt8x Firmware17/7/201717/6/2026
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.
ModificadaCrítica (9.8)1.7%—Oracle Glassfish Server17/7/201717/6/2026
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of administrative user and grant access to the web-based administration interface.
ModificadaAlta (7.5)8.3%💥 ExploitOracle Glassfish Server17/7/201717/6/2026
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.
ModificadaAlta (7.5)99%💥 ExploitOracle Glassfish Server17/7/201717/6/2026
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
AnalizadaCrítica (9.8)64%💥 ExploitThermofisher Dt80 DEX Firmware12/7/201717/6/2026
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.