Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Confluence Server CRITICAL 9.8
CVE-2019-3396 KEVEPSS 100%

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the …

Fix: 6.6.12 / 6.12.3+
Fix from $2,300 2019-03-25
Sourcetree HIGH 8.8
CVE-2018-20234EPSS 6%

There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repo…

Fix: 3.1.1+
Fix from $1,950 2019-03-08
Sourcetree HIGH 8.8
CVE-2018-20235EPSS 7%

There was an argument injection vulnerability in Atlassian Sourcetree for Windows from version 0.5a before version 3.0.15 via filenames in Mercurial …

Fix: 3.0.15+
Fix from $1,950 2019-03-08
Sourcetree HIGH 8.8
CVE-2018-20236EPSS 6%

There was an command injection vulnerability in Sourcetree for Windows from version 0.5a before version 3.0.10 via URI handling. A remote attacker co…

Fix: 3.0.10+
Fix from $1,950 2019-03-08
Crucible MEDIUM 5.4
CVE-2018-20241

The Edit upload resource for a review in Atlassian Fisheye and Crucible before version 4.7.0 allows remote attackers to inject arbitrary HTML or Java…

Fix: 4.7.0+
Fix from $1,600 2019-02-20
Crowd HIGH 8.1
CVE-2018-20238

Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate usi…

Fix: 3.2.7 / 3.3.4+
Fix from $1,950 2019-02-13
Confluence Data Center MEDIUM 6.5
CVE-2018-20237

Atlassian Confluence Server and Data Center before version 6.13.1 allows an authenticated user to download a deleted page via the word export feature.

Fix: 6.13.1 / 6.14.0+
Fix from $1,600 2019-02-13
Jira MEDIUM 5.4
CVE-2018-13403

The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13…

Fix: 7.6.10 / 7.13.1+
Fix from $1,600 2019-02-13
Jira MEDIUM 5.4
CVE-2018-20232

The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbit…

Fix: 7.6.11 / 7.13.1+
Fix from $1,600 2019-02-13
Universal Plugin Manager MEDIUM 6.5
CVE-2018-20233

The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privile…

Fix: 2.22.14+
Fix from $1,600 2019-01-18
Hipchat HIGH 8.8
CVE-2018-1000418

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…

Fix: after 2.2.0
Fix from $1,950 2019-01-09
Crowd2 HIGH 7.8
CVE-2018-1000423

An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, Crow…

Fix: after 2.0.0
Fix from $1,950 2019-01-09
Hipchat MEDIUM 6.5
CVE-2018-1000419

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall…

Fix: after 2.2.0
Fix from $1,600 2019-01-09
Crowd2 MEDIUM 6.5
CVE-2018-1000422

An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attacke…

Fix: after 2.0.0
Fix from $1,600 2019-01-09
Sourcetree HIGH 8.8
CVE-2018-13396

There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial re…

Fix: 3.0.0+
Fix from $1,950 2018-11-05
Sourcetree HIGH 8.8
CVE-2018-13397

There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercuria…

Fix: 3.0.0+
Fix from $1,950 2018-11-05
Jira MEDIUM 6.1
CVE-2018-13401

The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5…

Fix: 7.6.9 / 7.7.5+
Fix from $1,600 2018-10-23
Jira MEDIUM 6.1
CVE-2018-13402

Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version…

Fix: 7.6.9 / 7.7.5+
Fix from $1,600 2018-10-23
Crucible HIGH 7.8
CVE-2018-13399

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak…

Fix: 4.6.1+
Fix from $1,950 2018-10-16
Crucible MEDIUM 6.5
CVE-2018-13398

The administrative smart-commits resource in Atlassian Fisheye and Crucible before version 4.5.4 allows remote attackers to modify smart-commit setti…

Fix: 4.5.4+
Fix from $1,600 2018-09-18
Jira MEDIUM 6.1
CVE-2018-13395

Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from vers…

Fix: 7.6.8 / 7.7.5+
Fix from $1,600 2018-08-28
Jira MEDIUM 5.3
CVE-2018-13391

The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7…

Fix: 7.6.8 / 7.7.5+
Fix from $1,600 2018-08-28
Questions For Confluence MEDIUM 6.5
CVE-2018-13393

The convertCommentToAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated t…

Fix: 2.6.6+
Fix from $1,600 2018-08-15
Questions For Confluence MEDIUM 6.5
CVE-2018-13394

The acceptAnswer resource in Atlassian Confluence Questions before version 2.6.6, the bundled version of Confluence Questions was updated to a fixed …

Fix: 2.6.6+
Fix from $1,600 2018-08-15
Crucible MEDIUM 6.1
CVE-2018-13392

Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si…

Fix: 4.6.0+
Fix from $1,600 2018-08-13
Cloudtoken MEDIUM 6.1
CVE-2018-13390

Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain…

Fix: 0.1.24+
Fix from $1,600 2018-08-10
Sourcetree CRITICAL 9.8
CVE-2018-13385

There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit …

Fix: 2.7.6+
Fix from $2,300 2018-07-24
Sourcetree HIGH 8.1
CVE-2018-13386

There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commi…

Fix: 2.6.9+
Fix from $1,950 2018-07-24
Jira MEDIUM 5.9
CVE-2017-18104

The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to ob…

Fix: 7.6.7 / 7.11.0+
Fix from $1,600 2018-07-24
Jira MEDIUM 6.1
CVE-2018-5232

The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arb…

Fix: 7.6.7 / 7.10.1+
Fix from $1,600 2018-07-18