Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2017-9512
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive in…
Crucible
after 4.4.0
MEDIUM 5.4
CVE-2017-9507
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaS…
Crucible
after 4.4.0
MEDIUM 5.4
CVE-2017-9508
Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross si…
Crucible
Mitigation only
MEDIUM 5.4
CVE-2017-9509
The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross…
Crucible
after 4.4.0
MEDIUM 5.4
CVE-2017-9510
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cros…
Fisheye
after 4.4.0
MEDIUM 6.1
CVE-2017-9506EPSS 72%
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote a…
Oauth
No fix yet
HIGH 8.8
CVE-2017-8907
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and t…
Bamboo
Mitigation only
HIGH 8.8
CVE-2017-8080
Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving im…
Hipchat Server
after 2.2.3
MEDIUM 5.9
CVE-2017-8058
Acceptance of invalid/self-signed TLS certificates in Atlassian HipChat before 3.16.2 for iOS allows a man-in-the-middle and/or physically proximate …
Hipchat
after 3.16.1
CRITICAL 9.8
CVE-2017-8768EPSS 8%
Atlassian SourceTree v2.5c and prior are affected by a command injection in the handling of the sourcetree:// scheme. It will lead to arbitrary OS co…
Sourcetree
after 2.5c
HIGH 7.5
CVE-2017-7415
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
Confluence Server
No fix yet
CRITICAL 9.1
CVE-2017-7357
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a fil…
Hipchat Server
after 2.2.2
CRITICAL 9.8
CVE-2017-5983EPSS 16%
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers…
Jira
Mitigation only
HIGH 8.8
CVE-2016-4319
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
Jira
after 7.1.8
MEDIUM 5.4
CVE-2016-4317
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
Confluence
after 5.9.10
MEDIUM 6.1
CVE-2016-6285
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inj…
Jira
after 7.2.1
HIGH 7.5
CVE-2016-6668
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat …
Confluence Server
No fix yet
MEDIUM 6.1
CVE-2016-6283
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the…
Confluence
after 5.10.5
CRITICAL 9.8
CVE-2016-6496
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att…
Crowd
after 2.8.4
CRITICAL 9.8
CVE-2016-5229EPSS 7%
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers …
Bamboo
after 5.11.3
MEDIUM 6.1
CVE-2015-8398
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the…
Confluence
after 5.8.16
CRITICAL 9.1
CVE-2015-8361
Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers …
Bamboo
Patch available
CRITICAL 9.8
CVE-2015-8360
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serializ…
Bamboo
Patch available
CRITICAL 9.8
CVE-2014-9757
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execu…
Bamboo
Patch available
MEDIUM 6.5
CVE-2015-5603EPSS 59%
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors…
Hipchat
after 6.29.2
MEDIUM 6.8
CVE-2012-6342
Cross-site request forgery (CSRF) vulnerability in logout.action in Atlassian Confluence 3.4.6 allows remote attackers to hijack the authentication o…
Confluence Server
No fix yet
HIGH 7.5
CVE-2013-3926
Atlassian Crowd 2.6.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to a "symmetric backdoor." NOTE: as of 2…
Crowd
No fix yet
MEDIUM 5.8
CVE-2013-3925
Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to in…
Crowd
No fix yet
CRITICAL 9.1
CVE-2012-2926EPSS 67%
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, …
Bamboo
2.0.9 / 2.1.2+
MEDIUM 6.4
CVE-2012-2928
The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-part…
Jira
after 5.0.0