Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 16/9/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Atlassian Confluence Data CenterAI | 15/9/2026 | 17/9/2026 | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain… | |
| Pendiente de análisis | Crítica (9.3) | 0.51% | — | Atlassian Confluence Data CenterAIAtlassian Confluence ServerAI | 18/8/2026 | 26/8/2026 | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS,… | |
| Analizada | Alta (8.2) | 0.44% | — | Atlassian Confluence Data Center | 21/7/2026 | 11/8/2026 | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive… | |
| Analizada | Alta (7.1) | 0.43% | — | Atlassian Confluence Data Center | 21/7/2026 | 10/8/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable… | |
| Analizada | Alta (8.3) | 0.51% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 21/10/2025 | 30/9/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a… | |
| Analizada | Media (6.4) | 0.20% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 27/11/2024 | 17/6/2026 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about… | |
| Analizada | Alta (8.2) | 0.76% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 21/8/2024 | 17/6/2026 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. * Confluence Data Center and Server 7.19: Upgrade to a release greater than or… | |
| Modificada | Alta (8.7) | 0.89% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/7/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high… | |
| Modificada | Alta (8.8) | 88% | — | Atlassian Confluence Data CenterAtlassian Confluence ServerAtlassian FisheyeAtlassian Crucible+3 | 21/5/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 0.93% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 19/3/2024 | 17/6/2026 | This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high… | |
| Analizada | Alta (8.5) | 0.47% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 20/2/2024 | 17/6/2026 | This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to… | |
| Modificada | Alta (7.5) | 15% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services… | |
| Modificada | Alta (7.5) | 1.8% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an unauthenticated attacker to expose assets… | |
| Modificada | Alta (8.8) | 1.5% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in… | |
| Modificada | Alta (8.8) | 1.4% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by… | |
| Modificada | Alta (8.8) | 1.6% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 16/1/2024 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to… | |
| Modificada | Alta (8.8) | 13% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 6/12/2023 | 17/6/2026 | This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Atlassian Confluence Data CenterAtlassian Confluence Server | 31/10/2023 | 17/6/2026 | All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an attacker can then perform all administrative… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Atlassian Confluence Data CenterAtlassian Confluence Server | 4/10/2023 | 17/6/2026 | Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances.… | |
| Modificada | Alta (8.8) | 2.2% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Alta (8.8) | 2.1% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 18/7/2023 | 17/6/2026 | This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated attacker to execute arbitrary code which has high impact to… | |
| Modificada | Media (5.3) | 0.79% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 1/5/2023 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder… | |
| Modificada | Alta (7.5) | 0.86% | — | Atlassian Confluence Data Center | 15/11/2022 | 17/6/2026 | In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system. |