Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-26135EPSS 71% A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up fea… Jira Data Center 4.13.22 / 4.20.10+ Fix from $1,6002022-06-30 CRITICAL 9.8 CVE-2022-26134 KEVEPSS 100% In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to exe… Confluence Data Center 7.4.17 / 7.13.7+ Fix from $2,3002022-06-03 CRITICAL 9.8 CVE-2022-26133EPSS 71% SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 … Bitbucket Data Center 7.6.14 / 7.17.6+ Fix from $2,3002022-04-20 CRITICAL 9.8 CVE-2022-0540EPSS 88% A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This a… Jira Data Center 4.13.8 / 4.13.18+ Fix from $2,3002022-04-20 HIGH 8.8 CVE-2021-39114 Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arb… Confluence Data Center 6.13.23 / 7.4.11+ Fix from $1,9502022-04-05 CRITICAL 9.8 CVE-2021-43958 Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources … Crucible 4.8.9+ Fix from $2,3002022-03-16 HIGH 7.5 CVE-2021-43957 Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vuln… Crucible 4.8.9+ Fix from $1,9502022-03-16 MEDIUM 6.1 CVE-2021-43956 The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript vi… Crucible 4.8.9+ Fix from $1,6002022-03-16 HIGH 7.2 CVE-2021-43944 This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected ve… Jira Data Center 8.13.15 / 8.20.3+ Fix from $1,9502022-03-08 HIGH 7.8 CVE-2021-43940 Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local syst… Confluence Data Center 7.4.10 / 7.12.3+ Fix from $1,9502022-02-15 MEDIUM 6.5 CVE-2021-43941 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa an… Jira Data Center 8.13.5 / 8.20.3+ Fix from $1,6002022-02-15 HIGH 7.2 CVE-2021-43947 Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remot… Data Center 8.13.15 / 8.20.3+ Fix from $1,9502022-01-06 MEDIUM 6.5 CVE-2021-43946 Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator groups to filter subscriptions v… Jira Data Center 8.13.21 / 8.20.9+ Fix from $1,6002022-01-05 MEDIUM 6.1 CVE-2021-43942EPSS 55% Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site S… Jira Server 8.13.5 / 8.20.3+ Fix from $1,6002022-01-04 HIGH 7.5 CVE-2021-41311 Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to… Jira Software Data Center 8.19.1+ Fix from $1,9502021-12-08 MEDIUM 5.3 CVE-2021-41309 Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access revoked to export audit logs… Jira Software Data Center 8.19.1+ Fix from $1,6002021-12-08 HIGH 7.5 CVE-2021-41312 Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to e… Data Center 8.19.1+ Fix from $1,9502021-11-03 MEDIUM 6.1 CVE-2021-41310 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site S… Jira Software Data Center 8.5.19 / 8.13.11+ Fix from $1,6002021-11-01 HIGH 7.5 CVE-2021-41305 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an … Jira 8.13.12+ Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-41306 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure … Jira 8.13.12 / 8.20.0+ Fix from $1,9502021-10-26 HIGH 7.5 CVE-2021-41307 Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private f… Jira 8.13.12 / 8.20.0+ Fix from $1,9502021-10-26 MEDIUM 6.5 CVE-2021-41308 Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication se… Jira 8.6.0 / 8.13.12+ Fix from $1,6002021-10-26 MEDIUM 6.1 CVE-2021-41304 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site S… Data Center 8.13.12 / 8.20.2+ Fix from $1,6002021-10-26 MEDIUM 6.5 CVE-2021-39126 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cross-Site Request Forgery (CSRF)… Jira Data Center 8.5.10 / 8.13.1+ Fix from $1,6002021-10-21 MEDIUM 5.3 CVE-2021-39127 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access C… Jira 8.5.10 / 8.13.1+ Fix from $1,6002021-10-21 CRITICAL 9.8 CVE-2020-18683 Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling. Floodlight after 1.2 Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2020-18684 Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number. Floodlight after 1.2 Fix from $2,3002021-09-30 CRITICAL 9.8 CVE-2020-18685 Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP… Floodlight after 1.2 Fix from $2,3002021-09-30 HIGH 7.2 CVE-2021-39128 Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers with JIRA Administrators acc… Jira Data Center 8.13.12 / 8.19.1+ Fix from $1,9502021-09-16 MEDIUM 5.3 CVE-2021-39125 Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vul… Data Center 8.5.10 / 8.13.1+ Fix from $1,6002021-09-14