Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.6) | 0.31% | — | Atlassian Bamboo | 18/8/2026 | 2/9/2026 | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. * Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 * Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.10 | |
| Analizada | Crítica (9.4) | 1.3% | — | Atlassian Bamboo | 21/4/2026 | 10/8/2026 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of… | |
| Analizada | Alta (8.6) | 0.57% | — | Atlassian Bamboo | 17/3/2026 | 10/8/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the… | |
| Aplazada | Alta (7.3) | 0.56% | — | Bamboohr BuildAI | 1/4/2025 | 17/6/2026 | An issue in BambooHR Build v.25.0210.170831-83b08dd allows a remote attacker to escalate privileges via the /saml/index.php?r=" HTTP GET parameter. | |
| Aplazada | Media (6.5) | 0.33% | — | Bamboo Manchester Bamboo EnquiriesAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Manchester Bamboo Enquiries bamboo-enquiries allows Stored XSS.This issue affects Bamboo Enquiries: from n/a through <= 1.9.3. | |
| Modificada | Alta (8) | 2.7% | — | Atlassian Bamboo | 20/8/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to execute arbitrary code… | |
| Modificada | Alta (8.1) | 0.75% | — | Atlassian Bamboo | 16/7/2024 | 17/6/2026 | This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file,… | |
| Modificada | Media (5.4) | 0.38% | — | Bamboo MCR Bamboo Columns | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Mcr Bamboo Columns allows Stored XSS.This issue affects Bamboo Columns: from n/a through 1.6.1. | |
| Modificada | Media (5.4) | 0.42% | — | Bamboo MCR Bamboo Columns | 22/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bamboo Mcr Bamboo Columns plugin <= 1.6.1 versions. | |
| Modificada | Alta (8.8) | 1.2% | — | Atlassian Bamboo | 21/11/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Bamboo Data CenterAtlassian Bamboo Server | 19/7/2023 | 17/6/2026 | This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call… | |
| Modificada | Alta (8.8) | 2.3% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource… | |
| Modificada | Crítica (9.8) | 5.4% | — | Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+7 | 20/7/2022 | 17/6/2026 | A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.… | |
| Modificada | Media (5.3) | 1.1% | — | Atlassian Bamboo | 28/1/2021 | 17/6/2026 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory in disk and if certain files exists on the tmp directory, via a Sensitive Data Exposure vulnerability in the /chart endpoint. The affected versions are before version… | |
| Modificada | Media (4.3) | 1.3% | — | Atlassian Troubleshooting AND SupportAtlassian BambooAtlassian BitbucketAtlassian Confluence+4 | 8/11/2019 | 17/6/2026 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the… | |
| Modificada | Alta (8.8) | 2.7% | — | Atlassian Bamboo | 29/3/2018 | 17/6/2026 | Bamboo did not correctly check if a configured Mercurial repository URI contained values that the Windows operating system may consider argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan in Bamboo that has a non-linked Mercurial repository, or create a plan in… | |
| Modificada | Media (5.4) | 0.58% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The plan configure branches resource in Atlassian Bamboo before version 6.2.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a branch. | |
| Modificada | Media (6.1) | 0.81% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The signupUser resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the value of the csrf token cookie. | |
| Modificada | Alta (8.8) | 0.54% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The saveConfigureSecurity resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify security settings via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Alta (8.8) | 0.66% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The update user administration resource in Atlassian Bamboo before version 6.3.1 allows remote attackers to modify user data including passwords via a Cross-site request forgery (CSRF) vulnerability. | |
| Modificada | Media (5.4) | 0.61% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The viewDeploymentVersionJiraIssuesDialog resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release. | |
| Modificada | Media (5.4) | 0.61% | — | Atlassian Bamboo | 2/2/2018 | 17/6/2026 | The viewDeploymentVersionCommits resource in Atlassian Bamboo before version 6.2.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a release. | |
| Modificada | Crítica (9.1) | 2.4% | — | Atlassian Bamboo | 13/12/2017 | 17/6/2026 | Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least one linked Mercurial repository that the… | |
| Modificada | Crítica (9.6) | 1.9% | — | Atlassian Bamboo | 13/12/2017 | 17/6/2026 | It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute Java code of their choice on systems… | |
| Modificada | Alta (8.8) | 1.0% | — | Atlassian Bamboo | 12/10/2017 | 17/6/2026 | Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have… |