Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.3)0.74%💥 ExploitAtlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+45/10/20266/10/2026
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web…
Pendiente de análisisAlta (7.1)0.32%—Atlassian Jira Service Management Data CenterAI15/9/202617/9/2026
This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. * Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11
ModificadaAlta (8.8)88%💥 ExploitAtlassian Confluence Data CenterAtlassian Confluence ServerAtlassian FisheyeAtlassian Crucible+321/5/202417/6/2026
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to…
ModificadaCrítica (9.1)16%—Atlassian Jira Service Management1/2/202317/6/2026
An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service…
ModificadaMedia (4.3)0.63%—Atlassian Jira Service Management3/8/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse Users" permission to view groups via an Information Disclosure vulnerability in the browsegroups.action endpoint. The affected versions are before version 4.22.2.
ModificadaMedia (5.7)0.70%—Atlassian Jira Service DeskAtlassian Jira Service Management26/7/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this…
ModificadaAlta (8.8)2.4%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource…
ModificadaCrítica (9.8)5.5%—Atlassian BambooAtlassian BitbucketAtlassian Confluence Data CenterAtlassian Confluence Server+720/7/202217/6/2026
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting.…
ModificadaMedia (6.5)72%💥 PoCAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service DeskAtlassian Jira Service Management30/6/202217/6/2026
A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version…
ModificadaCrítica (9.8)88%💥 ExploitAtlassian Jira Data CenterAtlassian Jira ServerAtlassian Jira Service Management20/4/202217/6/2026
A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also…
ModificadaMedia (4.8)0.43%—Atlassian Jira Service Management24/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are…
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.84%—Atlassian Jira Service Management15/2/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.81%—Atlassian Jira Service Management10/1/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerability in the Create Object type mapping feature. The affected versions are before version 4.21.0.
ModificadaMedia (4.3)0.81%—Atlassian Jira Service Management10/1/202217/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Fields feature. The affected versions are before version 4.21.0.
ModificadaAlta (7.2)4.5%💥 PoCAtlassian Jira Service DeskAtlassian Jira Service Management1/9/202117/6/2026
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before…
ModificadaCrítica (9.8)50%—Atlassian Jira Data CenterAtlassian Jira Service DeskAtlassian Jira Service Management29/7/202117/6/2026
Jira Data Center, Jira Core Data Center, Jira Software Data Center from version 6.3.0 before 8.5.16, from 8.6.0 before 8.13.8, from 8.14.0 before 8.17.0 and Jira Service Management Data Center from version 2.0.2 before 4.5.16, from version 4.6.0 before 4.13.8, and from version 4.14.0 before 4.17.0 exposed a Ehcache…
ModificadaCrítica (9.8)16%💥 PoCSoftwareag QuartzOracle Apache Batik MapviewerOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+2726/7/201917/6/2026
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Orbitaley — Vulnerabilidades