Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-14175 Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scrip… Confluence Data Center 7.4.2 / 7.5.2+ Fix from $1,6002020-07-24 MEDIUM 6.1 CVE-2019-20901 The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a diffe… Jira 8.5.2+ Fix from $1,6002020-07-13 HIGH 7.5 CVE-2019-20898 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the … Jira 8.8.0+ Fix from $1,9502020-07-13 MEDIUM 5.3 CVE-2019-20899 The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests … Jira 8.5.4 / 8.6.1+ Fix from $1,6002020-07-13 MEDIUM 6.5 CVE-2019-20897 The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a cr… Jira 8.5.4 / 8.6.2+ Fix from $1,6002020-07-13 MEDIUM 6.5 CVE-2020-14171 Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a … Bitbucket 7.2.4+ Fix from $1,6002020-07-09 CRITICAL 9.8 CVE-2020-14172 This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. Th… Jira 7.13.0 / 8.5.0+ Fix from $2,3002020-07-03 HIGH 7.8 CVE-2019-20419 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomc… Jira Data Center 8.5.5 / 8.7.2+ Fix from $1,9502020-07-03 MEDIUM 5.4 CVE-2020-14173 The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript … Jira 8.5.4 / 8.6.2+ Fix from $1,6002020-07-03 MEDIUM 6.5 CVE-2019-20418 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Den… Jira 8.8.0+ Fix from $1,6002020-07-03 MEDIUM 6.1 CVE-2020-14169 The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a… Jira 8.9.1+ Fix from $1,6002020-07-01 MEDIUM 6.1 CVE-2020-4022 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allo… Jira 8.5.5 / 8.8.2+ Fix from $1,6002020-07-01 MEDIUM 5.4 CVE-2020-4024 The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allo… Jira 8.5.5 / 8.8.2+ Fix from $1,6002020-07-01 HIGH 7.5 CVE-2020-14167 The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8… Jira 7.13.14 / 8.5.5+ Fix from $1,9502020-07-01 MEDIUM 6.1 CVE-2020-14164 The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names … Jira 8.8.2+ Fix from $1,6002020-07-01 MEDIUM 5.9 CVE-2020-14168 The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1… Jira 7.13.14 / 8.5.5+ Fix from $1,6002020-07-01 MEDIUM 5.3 CVE-2019-20408 The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network reso… Jira 8.7.0+ Fix from $1,6002020-07-01 MEDIUM 5.3 CVE-2020-14165 The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information abo… Jira 8.9.0+ Fix from $1,6002020-07-01 MEDIUM 5.4 CVE-2019-20414 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (… Jira 7.13.9 / 8.4.2+ Fix from $1,6002020-06-29 HIGH 7.5 CVE-2019-20413 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (D… Jira 7.13.9 / 8.4.2+ Fix from $1,9502020-06-29 MEDIUM 6.5 CVE-2019-20410 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnera… Jira 7.6.17 / 7.13.9+ Fix from $1,6002020-06-29 MEDIUM 5.3 CVE-2019-20412 The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following in… Jira 7.13.9 / 8.4.2+ Fix from $1,6002020-06-29 MEDIUM 5.3 CVE-2020-4028 Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situati… Jira 8.9.1+ Fix from $1,6002020-06-23 CRITICAL 9.8 CVE-2019-20409 The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote… Jira 8.8.0+ Fix from $2,3002020-06-23 HIGH 7.8 CVE-2020-4019 The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable … Companion 1.0.0+ Fix from $1,9502020-06-01 HIGH 7.2 CVE-2020-4020 The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server insta… Companion 1.0.0+ Fix from $1,9502020-06-01 MEDIUM 5.4 CVE-2020-4021 Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary … Jira 7.13.16 / 8.5.5+ Fix from $1,6002020-06-01 MEDIUM 5.4 CVE-2020-4023 The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript vi… Crucible 4.8.2+ Fix from $1,6002020-06-01 HIGH 8.8 CVE-2020-4018 The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site req… Crucible 4.8.1+ Fix from $1,9502020-06-01 MEDIUM 5.4 CVE-2020-4013 The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross… Crucible 4.8.1+ Fix from $1,6002020-06-01