Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-21673 This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Exe… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 7.5 CVE-2024-21674 This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Exec… Confluence Data Center 7.19.18 / 8.5.5+ Fix from $1,9502024-01-16 HIGH 8.8 CVE-2023-22526 This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Exe… Confluence Data Center 7.19.17 / 8.5.5+ Fix from $1,9502024-01-16 CRITICAL 9.8 CVE-2023-22524EPSS 25% Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSocket… Companion 2.0.0+ Fix from $2,3002023-12-06 HIGH 8.8 CVE-2023-22523EPSS 11% This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent in… Assets Discovery Cloud 3.2.0 / 6.2.0+ Fix from $1,9502023-12-06 HIGH 8.8 CVE-2023-22522EPSS 13% This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confl… Confluence Data Center 7.19.17 / 8.4.5+ Fix from $1,9502023-12-06 HIGH 8.8 CVE-2023-22521 This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.6 of Crowd Data Center and Server. This RCE (Remote Cod… Crowd 5.1.6+ Fix from $1,9502023-11-21 HIGH 8.8 CVE-2023-22516 This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 8.1.0, 8.2.0, 9.0.0, 9.1.0, 9.2.0, and 9.3.0 of Bamboo Data C… Bamboo 9.2.7 / 9.3.4+ Fix from $1,9502023-11-21 CRITICAL 9.8 CVE-2023-22518 KEVEPSS 100% All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an… Confluence Data Center 7.19.16 / 8.3.4+ Fix from $2,3002023-10-31 CRITICAL 9.8 CVE-2023-22515 KEVEPSS 99% Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnera… Confluence Data Center 8.3.3 / 8.4.3+ Fix from $2,3002023-10-04 HIGH 8.8 CVE-2023-22513EPSS 14% This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Co… Bitbucket Data Center 8.9.5 / 8.10.5+ Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-22506 This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Cen… Bamboo Data Center 9.2.3+ Fix from $1,9502023-07-19 HIGH 8.8 CVE-2023-22508 This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Serv… Confluence Data Center 7.13.20 / 7.19.8+ Fix from $1,9502023-07-18 HIGH 8.8 CVE-2023-22505 This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Serv… Confluence Data Center 8.3.2+ Fix from $1,9502023-07-18 MEDIUM 6.5 CVE-2023-22504 Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload att… Confluence Server 7.13.17 / 7.19.9+ Fix from $1,6002023-05-25 MEDIUM 5.3 CVE-2023-22503 Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a pr… Confluence Data Center 7.13.15 / 7.19.7+ Fix from $1,6002023-05-01 CRITICAL 9.1 CVE-2023-22501EPSS 16% An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user… Jira Service Management 5.3.3 / 5.4.2+ Fix from $2,3002023-02-01 CRITICAL 9.8 CVE-2022-43781EPSS 98% There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control th… Bitbucket 7.6.19 / 7.17.12+ Fix from $2,3002022-11-17 CRITICAL 9.8 CVE-2022-43782 Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability … Crowd 4.4.4 / 5.0.3+ Fix from $2,3002022-11-17 HIGH 7.5 CVE-2022-42977 The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export i… Confluence Data Center 1.3.5+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-42978 In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on… Confluence Data Center 1.3.5+ Fix from $1,9502022-11-15 HIGH 8.8 CVE-2022-36803 The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use… Jira Align 10.109.2+ Fix from $1,9502022-10-14 HIGH 8.8 CVE-2022-36804 KEVEPSS 99% Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from ver… Bitbucket 7.6.17 / 7.17.10+ Fix from $1,9502022-08-25 MEDIUM 6.1 CVE-2022-36801EPSS 65% Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cr… Jira Data Center 8.20.8+ Fix from $1,6002022-08-10 HIGH 7.2 CVE-2022-36799EPSS 45% This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve… Jira Data Center 8.13.19 / 8.20.7+ Fix from $1,9502022-08-01 MEDIUM 5.7 CVE-2021-43959 Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal … Jira Service Desk 4.13.20 / 4.20.8+ Fix from $1,6002022-07-26 MEDIUM 5.4 CVE-2020-36290 The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before versio… Confluence Data Center 7.4.5 / 7.6.3+ Fix from $1,6002022-07-26 CRITICAL 9.8 CVE-2022-26136EPSS 5% A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps… Bamboo 4.3.8 / 4.4.2+ Fix from $2,3002022-07-20 CRITICAL 9.8 CVE-2022-26138 KEVEPSS 98% The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with… Questions For Confluence Patch available Fix from $2,3002022-07-20 HIGH 8.8 CVE-2022-26137 A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the a… Bamboo 4.3.8 / 4.4.2+ Fix from $1,9502022-07-20