Vulnerability index

Browse CVEs

366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2019-8444 The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote attackers to inject arbitrary HTM… Jira Server 7.13.6 / 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2019-8445 Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time… Jira Server 7.13.7 / 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 5.3 CVE-2019-8446EPSS 18% The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation c… Jira Server 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 6.1 CVE-2019-11584 The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scrip… Jira 8.3.2+ Fix from $1,6002019-08-23 MEDIUM 6.1 CVE-2019-11585 The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows r… Jira 7.13.6 / 8.2.3+ Fix from $1,6002019-08-23 MEDIUM 6.8 CVE-2019-15053 The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism v… Html Include And Replace Macro after 1.4.2 Fix from $1,6002019-08-14 MEDIUM 5.3 CVE-2019-8448 The login.jsp resource in Jira before version 7.13.4, and from version 8.0.0 before version 8.2.2 allows remote attackers to enumerate usernames via … Jira Server 7.13.4 / 8.2.2+ Fix from $1,6002019-08-13 CRITICAL 9.8 CVE-2019-11581 KEVEPSS 85% There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. A… Jira Server 7.6.14 / 7.13.5+ Fix from $2,3002019-08-09 MEDIUM 5.4 CVE-2018-20827 The activity stream gadget in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (X… Jira 7.13.1+ Fix from $1,6002019-08-09 MEDIUM 6.5 CVE-2019-11583 The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability… Jira 8.1.0+ Fix from $1,6002019-06-26 HIGH 8.8 CVE-2019-11582 An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to ga… Sourcetree 3.1.3+ Fix from $1,9502019-06-14 CRITICAL 9.8 CVE-2019-11580 KEVEPSS 95% Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attackers who can send unauthentic… Crowd 3.0.5 / 3.1.6+ Fix from $2,3002019-06-03 CRITICAL 9.1 CVE-2019-3397EPSS 5% Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.13.x), from 5.14.0 before 5.14… Bitbucket 5.13.6 / 5.14.4+ Fix from $2,3002019-06-03 HIGH 8.1 CVE-2019-8443 The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows … Jira 7.13.4 / 8.0.4+ Fix from $1,9502019-05-22 HIGH 7.5 CVE-2019-8442EPSS 60% The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 befor… Jira 7.13.4 / 8.0.4+ Fix from $1,9502019-05-22 MEDIUM 6.1 CVE-2019-3402EPSS 9% The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject ar… Jira 7.13.3 / 8.1.1+ Fix from $1,6002019-05-22 MEDIUM 5.3 CVE-2019-3401EPSS 13% The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate userna… Jira 7.13.3 / 8.1.1+ Fix from $1,6002019-05-22 MEDIUM 5.3 CVE-2019-3403EPSS 53% The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before versi… Jira 7.13.3 / 8.0.4+ Fix from $1,6002019-05-22 MEDIUM 6.1 CVE-2019-3400 The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to inject arbitrary HTML or Java… Jira Server 7.13.2 / 8.0.2+ Fix from $1,6002019-05-03 MEDIUM 6.1 CVE-2018-20824EPSS 38% The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting… Jira 7.13.1+ Fix from $1,6002019-05-03 HIGH 7.5 CVE-2019-3399 The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see informatio… Jira 7.13.2 / 8.0.2+ Fix from $1,9502019-04-30 MEDIUM 5.4 CVE-2018-20239 Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and fro… Application Links 3.4.3 / 4.7.0+ Fix from $1,6002019-04-30 HIGH 8.8 CVE-2019-3398 KEVEPSS 97% Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to … Confluence Server 6.6.13 / 6.12.4+ Fix from $1,9502019-04-18 HIGH 8.7 CVE-2017-18111 The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version … Application Links 5.0.10 / 5.1.3+ Fix from $1,9502019-03-29 HIGH 8.1 CVE-2017-18105 The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have prev… Crowd 3.0.2 / 3.1.1+ Fix from $1,9502019-03-29 HIGH 7.5 CVE-2017-18106 The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or… Crowd 2.9.1+ Fix from $1,9502019-03-29 HIGH 7.2 CVE-2017-18108 The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute… Crowd 2.10.2+ Fix from $1,9502019-03-29 MEDIUM 6.5 CVE-2017-18110 The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attacker… Crowd 3.0.2+ Fix from $1,6002019-03-29 MEDIUM 6.1 CVE-2017-18109 The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect… Crowd 3.0.2+ Fix from $1,6002019-03-29 CRITICAL 9.8 CVE-2019-3395EPSS 7% The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.… Confluence 6.6.12 / 6.12.3+ Fix from $2,3002019-03-25