Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Confluence Data Center CRITICAL 9.8
CVE-2023-22527 KEVEPSS 100%

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an aff…

Fix: 8.5.4+
Fix from $2,300 2024-01-16
Confluence Data Center CRITICAL 9.8
CVE-2023-22518 KEVEPSS 100%

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…

Fix: 7.19.16 / 8.3.4+
Fix from $2,300 2023-10-31
Confluence Data Center CRITICAL 9.8
CVE-2023-22515 KEVEPSS 99%

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera…

Fix: 8.3.3 / 8.4.3+
Fix from $2,300 2023-10-04
Bitbucket HIGH 8.8
CVE-2022-36804 KEVEPSS 99%

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver…

Fix: 7.6.17 / 7.17.10+
Fix from $1,950 2022-08-25
Questions For Confluence CRITICAL 9.8
CVE-2022-26138 KEVEPSS 98%

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with…

Patch available
Fix from $2,300 2022-07-20
Confluence Data Center CRITICAL 9.8
CVE-2022-26134 KEVEPSS 100%

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe…

Fix: 7.4.17 / 7.13.7+
Fix from $2,300 2022-06-03
Confluence Data Center CRITICAL 9.8
CVE-2021-26084 KEVEPSS 100%

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe…

Fix: 6.13.23 / 7.4.11+
Fix from $2,300 2021-08-30
Jira Data Center MEDIUM 5.3
CVE-2021-26086 KEVEPSS 100%

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the …

Fix: 8.5.14 / 8.13.6+
Fix from $1,600 2021-08-16
Confluence Data Center MEDIUM 5.3
CVE-2021-26085 KEVEPSS 100%

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vuln…

Fix: 7.4.10 / 7.12.3+
Fix from $1,600 2021-08-03
Jira Server CRITICAL 9.8
CVE-2019-11581 KEVEPSS 85%

There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A…

Fix: 7.6.14 / 7.13.5+
Fix from $2,300 2019-08-09
Crowd CRITICAL 9.8
CVE-2019-11580 KEVEPSS 95%

Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic…

Fix: 3.0.5 / 3.1.6+
Fix from $2,300 2019-06-03
Confluence Server HIGH 8.8
CVE-2019-3398 KEVEPSS 97%

Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to …

Fix: 6.6.13 / 6.12.4+
Fix from $1,950 2019-04-18
Confluence Server CRITICAL 9.8
CVE-2019-3396 KEVEPSS 100%

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the …

Fix: 6.6.12 / 6.12.3+
Fix from $2,300 2019-03-25