VYPR

Vendor CVEs

Atlassian

All CVEs

507 total · sorted by risk
  • CVE-2017-8080HigMay 5, 2017
    risk 0.57cvss 8.8epss 0.03

    Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads.

  • CVE-2016-4319HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.01

    Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.

  • CVE-2024-21678HigFeb 20, 2024
    risk 0.55cvss 8.5epss 0.00

    This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high…

  • CVE-2017-16857HigDec 5, 2017
    risk 0.55cvss 8.5epss 0.01

    It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the auto-unapprove plugin,…

  • CVE-2023-50930HigJan 9, 2024
    risk 0.54cvss 8.3epss 0.00

    An issue was discovered in savignano S/Notify before 4.0.2 for Jira. While an administrative user is logged on, the configuration settings of S/Notify can be modified via a CSRF attack. The injection could be initiated by the administrator clicking a malicious link in an email…

  • CVE-2019-8442HigMay 22, 2019
    risk 0.54cvss 7.5epss 0.60

    The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access…

  • CVE-2025-35115HigAug 26, 2025
    risk 0.53cvss 8.1epss 0.00

    Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30.

  • CVE-2024-21690HigAug 21, 2024
    risk 0.53cvss 8.2epss 0.01

    This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, 7.20.0, 8.0.0, 8.1.0, 8.2.0, 8.3.0, 8.4.0, 8.5.0, 8.6.0, 8.7.1, 8.8.0, and 8.9.0 of Confluence Data Center and Server. This Reflected XSS and CSRF…

  • CVE-2024-21687HigJul 16, 2024
    risk 0.53cvss 8.1epss 0.01

    This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application…

  • CVE-2023-26255HigFeb 28, 2023
    risk 0.53cvss 7.5epss 0.47

    An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjCustomDesignConfig endpoint, it is possible to traverse and read the file system.

  • CVE-2020-15943HigAug 4, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this…

  • CVE-2019-8443HigMay 22, 2019
    risk 0.53cvss 8.1epss 0.03

    The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without…

  • CVE-2017-18105HigMar 29, 2019
    risk 0.53cvss 8.1epss 0.01

    The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via…

  • CVE-2018-20238HigFeb 13, 2019
    risk 0.53cvss 8.1epss 0.02

    Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability.

  • CVE-2018-13386HigJul 24, 2018
    risk 0.53cvss 8.1epss 0.02

    There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.…

  • CVE-2026-21575HigJul 21, 2026
    risk 0.52cvss 8.0epss 0.00

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary…

  • CVE-2024-21689HigAug 20, 2024
    risk 0.52cvss 8.0epss 0.03

    This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.6, allows an…

  • CVE-2026-21569HigJan 28, 2026
    risk 0.51cvss 7.9epss 0.00

    This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote…

  • CVE-2023-22514HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of:…

  • CVE-2023-42361HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.01

    Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.

  • CVE-2021-43940HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence…

  • CVE-2020-36233HigFeb 18, 2021
    risk 0.51cvss 7.8epss 0.00

    The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

  • CVE-2019-20419HigJul 3, 2020
    risk 0.51cvss 7.8epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomcat. The affected versions are before version 8.5.5, and from version 8.6.0 before 8.7.2.

  • CVE-2020-4019HigJun 1, 2020
    risk 0.51cvss 7.8epss 0.00

    The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.

  • CVE-2019-20406HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable…

  • CVE-2019-20400HigFeb 6, 2020
    risk 0.51cvss 7.8epss 0.00

    The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.

  • CVE-2018-13399HigOct 16, 2018
    risk 0.51cvss 7.8epss 0.00

    The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.

  • CVE-2023-22512HigJan 16, 2024
    risk 0.50cvss 7.5epss 0.14

    This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by…

  • CVE-2023-26256HigFeb 28, 2023
    risk 0.50cvss 7.5epss 0.12

    An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2.0.52 for Jira. By modifying the fileName parameter to the snjFooterNavigationConfig endpoint, it is possible to traverse and read the file system.

  • CVE-2022-36799HigAug 1, 2022
    risk 0.50cvss 7.2epss 0.45

    This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute…

  • CVE-2021-26073HigApr 16, 2021
    risk 0.50cvss 7.7epss 0.01

    Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a…

  • CVE-2019-8451MedSep 11, 2019
    risk 0.50cvss 6.5epss 0.94

    The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class.

  • CVE-2026-21579HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an…

  • CVE-2025-22166HigOct 21, 2025
    risk 0.49cvss 7.5epss 0.00

    This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 8.3, allows an attacker to cause a resource to be unavailable for its intended users by…

  • CVE-2025-35114HigAug 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The password hash is known for at least one of the accounts and the credentials could be cracked offline. Users should upgrade to Agiloft Release 30.

  • CVE-2024-21674HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an…

  • CVE-2022-42978HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.

  • CVE-2022-42977HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g., an SSH private key) to be…

  • CVE-2021-43957HigMar 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are…

  • CVE-2021-41311HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that has had its access revoked to modify projects' Users & Roles settings, via a Broken Authentication vulnerability in the /plugins/servlet/project-config/PROJECT/…

  • CVE-2021-41312HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the…

  • CVE-2021-41307HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are…

  • CVE-2021-41306HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version…

  • CVE-2021-41305HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are…

  • CVE-2021-39123HigSep 14, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before…

  • CVE-2021-39109HigSep 1, 2021
    risk 0.49cvss 7.5epss 0.02

    The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary files via a path traversal vulnerability.

  • CVE-2021-39113HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and…

  • CVE-2020-14190HigNov 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.

  • CVE-2020-14191HigNov 25, 2020
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are before version 4.8.4.

  • CVE-2019-20902HigOct 1, 2020
    risk 0.49cvss 7.5epss 0.01

    Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1.

Page 3 of 11