Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jira Data Center MEDIUM 6.5
CVE-2022-26135EPSS 71%

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up fea…

Fix: 4.13.22 / 4.20.10+
Fix from $1,600 2022-06-30
Confluence Data Center CRITICAL 9.8
CVE-2022-26134 KEVEPSS 100%

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe…

Fix: 7.4.17 / 7.13.7+
Fix from $2,300 2022-06-03
Bitbucket Data Center CRITICAL 9.8
CVE-2022-26133EPSS 71%

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 …

Fix: 7.6.14 / 7.17.6+
Fix from $2,300 2022-04-20
Jira Data Center CRITICAL 9.8
CVE-2022-0540EPSS 88%

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This a…

Fix: 4.13.8 / 4.13.18+
Fix from $2,300 2022-04-20
Confluence Data Center HIGH 8.8
CVE-2021-39114

Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arb…

Fix: 6.13.23 / 7.4.11+
Fix from $1,950 2022-04-05
Crucible CRITICAL 9.8
CVE-2021-43958

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources …

Fix: 4.8.9+
Fix from $2,300 2022-03-16
Crucible HIGH 7.5
CVE-2021-43957

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vuln…

Fix: 4.8.9+
Fix from $1,950 2022-03-16
Crucible MEDIUM 6.1
CVE-2021-43956

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript vi…

Fix: 4.8.9+
Fix from $1,600 2022-03-16
Jira Data Center HIGH 7.2
CVE-2021-43944

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve…

Fix: 8.13.15 / 8.20.3+
Fix from $1,950 2022-03-08
Confluence Data Center HIGH 7.8
CVE-2021-43940

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local syst…

Fix: 7.4.10 / 7.12.3+
Fix from $1,950 2022-02-15
Jira Data Center MEDIUM 6.5
CVE-2021-43941

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa an…

Fix: 8.13.5 / 8.20.3+
Fix from $1,600 2022-02-15
Data Center HIGH 7.2
CVE-2021-43947

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remot…

Fix: 8.13.15 / 8.20.3+
Fix from $1,950 2022-01-06
Jira Data Center MEDIUM 6.5
CVE-2021-43946

Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions v…

Fix: 8.13.21 / 8.20.9+
Fix from $1,600 2022-01-05
Jira Server MEDIUM 6.1
CVE-2021-43942EPSS 55%

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site S…

Fix: 8.13.5 / 8.20.3+
Fix from $1,600 2022-01-04
Jira Software Data Center HIGH 7.5
CVE-2021-41311

Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to…

Fix: 8.19.1+
Fix from $1,950 2021-12-08
Jira Software Data Center MEDIUM 5.3
CVE-2021-41309

Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs…

Fix: 8.19.1+
Fix from $1,600 2021-12-08
Data Center HIGH 7.5
CVE-2021-41312

Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to e…

Fix: 8.19.1+
Fix from $1,950 2021-11-03
Jira Software Data Center MEDIUM 6.1
CVE-2021-41310

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site S…

Fix: 8.5.19 / 8.13.11+
Fix from $1,600 2021-11-01
Jira HIGH 7.5
CVE-2021-41305

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an …

Fix: 8.13.12+
Fix from $1,950 2021-10-26
Jira HIGH 7.5
CVE-2021-41306

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure …

Fix: 8.13.12 / 8.20.0+
Fix from $1,950 2021-10-26
Jira HIGH 7.5
CVE-2021-41307

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private f…

Fix: 8.13.12 / 8.20.0+
Fix from $1,950 2021-10-26
Jira MEDIUM 6.5
CVE-2021-41308

Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication se…

Fix: 8.6.0 / 8.13.12+
Fix from $1,600 2021-10-26
Data Center MEDIUM 6.1
CVE-2021-41304

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site S…

Fix: 8.13.12 / 8.20.2+
Fix from $1,600 2021-10-26
Jira Data Center MEDIUM 6.5
CVE-2021-39126

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF)…

Fix: 8.5.10 / 8.13.1+
Fix from $1,600 2021-10-21
Jira MEDIUM 5.3
CVE-2021-39127

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access C…

Fix: 8.5.10 / 8.13.1+
Fix from $1,600 2021-10-21
Floodlight CRITICAL 9.8
CVE-2020-18683

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.

Fix: after 1.2
Fix from $2,300 2021-09-30
Floodlight CRITICAL 9.8
CVE-2020-18684

Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.

Fix: after 1.2
Fix from $2,300 2021-09-30
Floodlight CRITICAL 9.8
CVE-2020-18685

Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP…

Fix: after 1.2
Fix from $2,300 2021-09-30
Jira Data Center HIGH 7.2
CVE-2021-39128

Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators acc…

Fix: 8.13.12 / 8.19.1+
Fix from $1,950 2021-09-16
Data Center MEDIUM 5.3
CVE-2021-39125

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vul…

Fix: 8.5.10 / 8.13.1+
Fix from $1,600 2021-09-14