Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2020-36286
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.…
Data Center
8.5.13 / 8.13.5+
HIGH 7.2
CVE-2021-26070
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via…
Data Center
8.13.3 / 8.14.1+
MEDIUM 5.3
CVE-2021-26069
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project k…
Data Center
8.5.11 / 8.13.3+
MEDIUM 5.3
CVE-2020-36240
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to …
Crowd
4.0.4 / 4.1.2+
HIGH 8.8
CVE-2021-26068
An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers to execute arbitrary code via …
Jira Server For Slack
2.0.15+
MEDIUM 5.3
CVE-2020-29448
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and…
Confluence Data Center
6.13.18 / 7.4.6+
MEDIUM 5.3
CVE-2020-29453EPSS 23%
The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 bef…
Data Center
8.5.11 / 8.13.3+
MEDIUM 5.0
CVE-2020-36232
The MessageBundleWhiteList class of atlassian-gadgets before version 4.2.37, from version 4.3.0 before 4.3.14, from version 4.3.2.0 before 4.3.2.4, f…
Atlassian Gadgets
4.2.37 / 4.3.2.4+
HIGH 8.8
CVE-2020-12873
An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a w…
Alfresco Enterprise Content Management
6.2.1+
HIGH 7.8
CVE-2020-36233
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before…
Bitbucket
6.10.9 / 7.6.4+
MEDIUM 6.1
CVE-2020-36236
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (…
Jira
8.5.11 / 8.13.3+
MEDIUM 5.3
CVE-2020-36235
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an In…
Jira
8.13.2 / 8.14.1+
MEDIUM 5.3
CVE-2020-36237
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Dis…
Data Center
8.15.0+
MEDIUM 5.3
CVE-2021-26067
Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the path for the home directory …
Bamboo
7.2.2+
MEDIUM 6.5
CVE-2020-29450
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Serv…
Confluence Data Center
7.2.0+
MEDIUM 5.3
CVE-2020-29446
Affected versions of Atlassian Fisheye & Crucible allow remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulner…
Crucible
4.8.5+
MEDIUM 5.4
CVE-2020-14193
Affected versions of Automation for Jira - Server allowed remote attackers to read and render files as mustache templates in files inside the WEB-INF…
Automation For Jira
7.1.15+
HIGH 7.5
CVE-2020-14190
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affec…
Crucible
4.8.4+
HIGH 7.5
CVE-2020-14191
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnera…
Crucible
4.8.4+
CRITICAL 9.8
CVE-2020-14188
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in th…
Jira Create
2.0.1+
CRITICAL 9.8
CVE-2020-14189
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the c…
Jira Comment
2.0.2+
MEDIUM 5.3
CVE-2020-14185
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOper…
Jira
7.13.18 / 8.5.9+
MEDIUM 5.4
CVE-2020-14184
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerabili…
Jira
8.5.9 / 8.12.3+
HIGH 7.5
CVE-2019-20902
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.…
Crowd
3.4.6 / 3.5.1+
MEDIUM 5.4
CVE-2019-20903
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a C…
Editor Core
113.1.5+
MEDIUM 6.5
CVE-2020-14177
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Regex-based Denial o…
Jira Server
7.13.16 / 8.5.7+
MEDIUM 5.3
CVE-2020-14179EPSS 76%
Affected versions of Atlassian Jira Server and Data Center allow remote, unauthenticated attackers to view custom field names and custom SLA names vi…
Jira Data Center
8.5.8 / 8.11.1+
MEDIUM 5.3
CVE-2020-14181EPSS 100%
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerabili…
Data Center
7.13.6 / 8.5.7+
HIGH 7.5
CVE-2020-14178
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerabili…
Jira
7.13.7 / 8.5.8+
MEDIUM 6.5
CVE-2017-18112
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability i…
Fisheye
4.8.3+