Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

597 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.5%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.…
ModificadaMedia (6.5)72%💥 PoCAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service DeskAtlassian Jira Service Management30/6/202217/6/2026
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version…
ModificadaAlta (8.8)0.66%—Atlasvpn21/6/202217/6/2026
AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed.
ModificadaMedia (4.8)0.51%—Atlasgondal Export ALL Urls15/6/202217/6/2026
Authenticated (editor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Export All URLs plugin <= 4.1 at WordPress.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAtlassian Confluence Data CenterAtlassian Confluence Server3/6/202217/6/2026
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before…
ModificadaCrítica (9.8)70%💥 PoCAtlassian Bitbucket Data Center20/4/202217/6/2026
SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.
ModificadaCrítica (9.8)88%💥 ExploitAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service Management20/4/202217/6/2026
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also…
ModificadaMedia (6.5)0.65%—Atlasgondal Export ALL Urls11/4/202217/6/2026
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
ModificadaMedia (6.1)0.80%—Atlasgondal Export ALL Urls11/4/202217/6/2026
The Export All URLs WordPress plugin before 4.2 does not sanitise and escape the CSV filename before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)1.7%—Atlassian Confluence Data CenterAtlassian Confluence Server5/4/202217/6/2026
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from…
ModificadaCrítica (9.8)1.5%—Atlassian CrucibleAtlassian Fisheye16/3/202217/6/2026
Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via…
ModificadaAlta (7.5)1.3%—Atlassian CrucibleAtlassian Fisheye16/3/202217/6/2026
Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.
ModificadaMedia (6.1)0.73%—Atlassian CrucibleAtlassian Fisheye16/3/202217/6/2026
The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.
ModificadaMedia (4.3)0.88%—Atlassian CrucibleAtlassian Fisheye16/3/202217/6/2026
The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.
ModificadaMedia (4.3)0.77%—Atlassian CrucibleAtlassian Fisheye14/3/202217/6/2026
The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.
ModificadaAlta (7.2)2.3%—Atlassian Jira Data CenterAtlassian Jira Server8/3/202217/6/2026
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to…
ModificadaMedia (4.8)0.57%—Atlassian Data CenterAtlassian Jira28/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.
ModificadaMedia (4.8)0.43%—Atlassian Jira Service Management24/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are…
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
ModificadaMedia (6.5)0.62%—Atlassian Jira Data CenterAtlassian Jira Server15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15,…
ModificadaAlta (7.8)0.33%—Atlassian Confluence Data CenterAtlassian Confluence Server15/2/202217/6/2026
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The…
ModificadaMedia (4.3)0.48%—Atlassian Data CenterAtlassian Jira15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16,…
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.41%—Atlassian Jira Data CenterAtlassian Jira Server15/2/202217/6/2026
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.
ModificadaMedia (4.3)0.81%—Atlassian Jira Service Management10/1/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.
Orbitaley — Vulnerabilidades