Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

293 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.3)——Atlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+45/10/20265/10/2026
h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within…
Pendiente de análisisAlta (7.1)0.32%—Atlassian Jira Service Management Data CenterAI15/9/202617/9/2026
This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11
AplazadaAlta (7.7)0.48%—MCP AtlassianAIAtlassian ConfluenceAIAtlassian JiraAI14/9/202630/9/2026
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the confluence_upload_attachment and confluence_upload_attachments tools pass a client-controlled file_path through src/mcp_atlassian/confluence/attachments.py upload_attachment, and the…
AplazadaAlta (7.7)0.48%—MCP AtlassianAIAtlassian ConfluenceAIAtlassian JiraAI12/8/202618/9/2026
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through _upload_attachment_direct() without calling…
AplazadaBaja (1.9)0.15%—Ks-gen-ai Jira-mcp-serverAI9/8/202612/8/2026
A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a local approach. The project was informed of…
AplazadaMedia (6.4)0.16%—Jiransoft Appcheck PROAI3/8/202612/8/2026
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component Kernel Mini-Filter Driver. Performing a manipulation results in uncontrolled search path. The attack requires a local approach. The complexity of an attack is rather…
AplazadaAlta (8.7)0.48%—Syracom AG Secure Login 2FAAIAtlassian JiraAIAtlassian ConfluenceAIAtlassian BitbucketAI16/6/202621/6/2026
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings…
AnalizadaCrítica (9.1)0.80%—Microsoft Confluence Saml SSOMicrosoft Jira Saml SSO12/5/202617/6/2026
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.9)0.45%—FirefighterAIJiraAIAmazon AWSAI11/5/202617/6/2026
FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = [permissions.AllowAny]). Its attachments payload is fetched server-side via httpx.get() with no URL validation, then…
AnalizadaMedia (6.1)0.32%—Jirafeau28/1/202617/6/2026
Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents could be exploited for cross site scripting. This was done by storing the MIME type of a file and allowing only browser preview for MIME types beginning with image (except for image/svg+xml, see…
AplazadaMedia (6.1)0.24%—Tempo WorklogproAIAtlassian JiraAI20/1/202617/6/2026
The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 allows attackers to inject arbitrary HTML or JavaScript via XSS. This is exploited via a crafted payload placed in the name of a filter. This code is executed in the browser when the user attempts to…
AnalizadaMedia (4.3)0.34%—Jenkins Redpen - Pipeline Reporter FOR Jira10/12/202517/6/2026
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller workspace directory.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
ModificadaMedia (5.3)0.18%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
AnalizadaMedia (5.3)0.19%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
AnalizadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
AnalizadaMedia (5.3)0.18%—Atlassian Jira Align22/10/202517/6/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
ModificadaMedia (5.3)0.21%—Atlassian Jira Align22/10/202530/9/2026
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
AnalizadaAlta (8.7)0.50%—Atlassian Jira Data CenterAtlassian Jira Server22/10/202517/6/2026
This High severity Path Traversal (Arbitrary Write) vulnerability was introduced in versions: 9.12.0, 10.3.0 and remain present in 11.0.0 of Jira Software Data Center and Server. This Path Traversal (Arbitrary Write) vulnerability, with a CVSS Score of 8.7, allows an attacker to modify any filesystem path writable by…
AplazadaBaja (2.3)0.22%—Jiransoft Crosseditor4AI15/7/202517/6/2026
The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XSS. This issue affects CrossEditor4: from 4.0.0.01 before 4.6.0.23.