Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.5% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.… | |
| Modificada | Media (6.5) | 72% | 💥 PoC | Atlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service DeskAtlassian Jira Service Management | 30/6/2022 | 17/6/2026 | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version… | |
| Modificada | Alta (8.8) | 0.66% | — | Atlasvpn | 21/6/2022 | 17/6/2026 | AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed. | |
| Modificada | Media (4.8) | 0.51% | — | Atlasgondal Export ALL Urls | 15/6/2022 | 17/6/2026 | Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Atlassian Confluence Data CenterAtlassian Confluence Server | 3/6/2022 | 17/6/2026 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before… | |
| Modificada | Crítica (9.8) | 70% | 💥 PoC | Atlassian Bitbucket Data Center | 20/4/2022 | 17/6/2026 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization. | |
| Modificada | Crítica (9.8) | 88% | 💥 Exploit | Atlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service Management | 20/4/2022 | 17/6/2026 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also… | |
| Modificada | Media (6.5) | 0.65% | — | Atlasgondal Export ALL Urls | 11/4/2022 | 17/6/2026 | The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example | |
| Modificada | Media (6.1) | 0.80% | — | Atlasgondal Export ALL Urls | 11/4/2022 | 17/6/2026 | The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 1.7% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 5/4/2022 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from… | |
| Modificada | Crítica (9.8) | 1.5% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via… | |
| Modificada | Alta (7.5) | 1.3% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9. | |
| Modificada | Media (6.1) | 0.73% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability. | |
| Modificada | Media (4.3) | 0.88% | — | Atlassian CrucibleAtlassian Fisheye | 16/3/2022 | 17/6/2026 | The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability. | |
| Modificada | Media (4.3) | 0.77% | — | Atlassian CrucibleAtlassian Fisheye | 14/3/2022 | 17/6/2026 | The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability. | |
| Modificada | Alta (7.2) | 2.3% | — | Atlassian Jira Data CenterAtlassian Jira Server | 8/3/2022 | 17/6/2026 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to… | |
| Modificada | Media (4.8) | 0.57% | — | Atlassian Data CenterAtlassian Jira | 28/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3. | |
| Modificada | Media (4.8) | 0.43% | — | Atlassian Jira Service Management | 24/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are… | |
| Modificada | Media (4.3) | 0.84% | — | Atlassian Jira Service Management | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0. | |
| Modificada | Media (6.5) | 0.62% | — | Atlassian Jira Data CenterAtlassian Jira Server | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15,… | |
| Modificada | Alta (7.8) | 0.33% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The… | |
| Modificada | Media (4.3) | 0.48% | — | Atlassian Data CenterAtlassian Jira | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16,… | |
| Modificada | Media (4.3) | 0.84% | — | Atlassian Jira Service Management | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0. | |
| Modificada | Media (4.3) | 0.41% | — | Atlassian Jira Data CenterAtlassian Jira Server | 15/2/2022 | 17/6/2026 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0. | |
| Modificada | Media (4.3) | 0.81% | — | Atlassian Jira Service Management | 10/1/2022 | 17/6/2026 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0. |