Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confluence Data Center HIGH 8.8
CVE-2024-21673

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Exe…

Fix: 7.19.18 / 8.5.5+
Fix from $1,950 2024-01-16
Confluence Data Center HIGH 7.5
CVE-2024-21674

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Exec…

Fix: 7.19.18 / 8.5.5+
Fix from $1,950 2024-01-16
Confluence Data Center HIGH 8.8
CVE-2023-22526

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Exe…

Fix: 7.19.17 / 8.5.5+
Fix from $1,950 2024-01-16
Companion CRITICAL 9.8
CVE-2023-22524EPSS 25%

Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSocket…

Fix: 2.0.0+
Fix from $2,300 2023-12-06
Assets Discovery Cloud HIGH 8.8
CVE-2023-22523EPSS 11%

This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent in…

Fix: 3.2.0 / 6.2.0+
Fix from $1,950 2023-12-06
Confluence Data Center HIGH 8.8
CVE-2023-22522EPSS 13%

This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confl…

Fix: 7.19.17 / 8.4.5+
Fix from $1,950 2023-12-06
Crowd HIGH 8.8
CVE-2023-22521

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Cod…

Fix: 5.1.6+
Fix from $1,950 2023-11-21
Bamboo HIGH 8.8
CVE-2023-22516

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data C…

Fix: 9.2.7 / 9.3.4+
Fix from $1,950 2023-11-21
Confluence Data Center CRITICAL 9.8
CVE-2023-22518 KEVEPSS 100%

All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an…

Fix: 7.19.16 / 8.3.4+
Fix from $2,300 2023-10-31
Confluence Data Center CRITICAL 9.8
CVE-2023-22515 KEVEPSS 99%

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera…

Fix: 8.3.3 / 8.4.3+
Fix from $2,300 2023-10-04
Bitbucket Data Center HIGH 8.8
CVE-2023-22513EPSS 14%

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Co…

Fix: 8.9.5 / 8.10.5+
Fix from $1,950 2023-09-19
Bamboo Data Center HIGH 8.8
CVE-2023-22506

This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Cen…

Fix: 9.2.3+
Fix from $1,950 2023-07-19
Confluence Data Center HIGH 8.8
CVE-2023-22508

This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Serv…

Fix: 7.13.20 / 7.19.8+
Fix from $1,950 2023-07-18
Confluence Data Center HIGH 8.8
CVE-2023-22505

This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Serv…

Fix: 8.3.2+
Fix from $1,950 2023-07-18
Confluence Server MEDIUM 6.5
CVE-2023-22504

Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload att…

Fix: 7.13.17 / 7.19.9+
Fix from $1,600 2023-05-25
Confluence Data Center MEDIUM 5.3
CVE-2023-22503

Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pr…

Fix: 7.13.15 / 7.19.7+
Fix from $1,600 2023-05-01
Jira Service Management CRITICAL 9.1
CVE-2023-22501EPSS 16%

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user…

Fix: 5.3.3 / 5.4.2+
Fix from $2,300 2023-02-01
Bitbucket CRITICAL 9.8
CVE-2022-43781EPSS 98%

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control th…

Fix: 7.6.19 / 7.17.12+
Fix from $2,300 2022-11-17
Crowd CRITICAL 9.8
CVE-2022-43782

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability …

Fix: 4.4.4 / 5.0.3+
Fix from $2,300 2022-11-17
Confluence Data Center HIGH 7.5
CVE-2022-42977

The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export i…

Fix: 1.3.5+
Fix from $1,950 2022-11-15
Confluence Data Center HIGH 7.5
CVE-2022-42978

In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on…

Fix: 1.3.5+
Fix from $1,950 2022-11-15
Jira Align HIGH 8.8
CVE-2022-36803

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use…

Fix: 10.109.2+
Fix from $1,950 2022-10-14
Bitbucket HIGH 8.8
CVE-2022-36804 KEVEPSS 99%

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver…

Fix: 7.6.17 / 7.17.10+
Fix from $1,950 2022-08-25
Jira Data Center MEDIUM 6.1
CVE-2022-36801EPSS 65%

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cr…

Fix: 8.20.8+
Fix from $1,600 2022-08-10
Jira Data Center HIGH 7.2
CVE-2022-36799EPSS 45%

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve…

Fix: 8.13.19 / 8.20.7+
Fix from $1,950 2022-08-01
Jira Service Desk MEDIUM 5.7
CVE-2021-43959

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal …

Fix: 4.13.20 / 4.20.8+
Fix from $1,600 2022-07-26
Confluence Data Center MEDIUM 5.4
CVE-2020-36290

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before versio…

Fix: 7.4.5 / 7.6.3+
Fix from $1,600 2022-07-26
Bamboo CRITICAL 9.8
CVE-2022-26136EPSS 5%

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps…

Fix: 4.3.8 / 4.4.2+
Fix from $2,300 2022-07-20
Questions For Confluence CRITICAL 9.8
CVE-2022-26138 KEVEPSS 98%

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with…

Patch available
Fix from $2,300 2022-07-20
Bamboo HIGH 8.8
CVE-2022-26137

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a…

Fix: 4.3.8 / 4.4.2+
Fix from $1,950 2022-07-20