CVE & Exploit Intelligence Database

Updated 56m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
13 results Clear all
CVE-2025-22178 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
CWE-862 Oct 22, 2025
CVE-2025-22177 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
CWE-285 Oct 22, 2025
CVE-2025-22176 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
CWE-285 Oct 22, 2025
CVE-2025-22175 5.4 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
CWE-285 Oct 22, 2025
CVE-2025-22174 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
CWE-285 Oct 22, 2025
CVE-2025-22173 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
CWE-285 Oct 22, 2025
CVE-2025-22172 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
CWE-285 Oct 22, 2025
CVE-2025-22171 4.3 MEDIUM EPSS 0.00
Jira Align - Auth Bypass
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
CWE-285 Oct 22, 2025
CVE-2025-22170 4.3 MEDIUM EPSS 0.00
Jira Align - Auth Bypass
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
CWE-285 Oct 22, 2025
CVE-2025-22169 5.4 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
CWE-285 Oct 22, 2025
CVE-2025-22168 4.3 MEDIUM EPSS 0.00
Jira Align - Info Disclosure
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
CWE-285 Oct 22, 2025
CVE-2022-36803 8.8 HIGH EPSS 0.00
Atlassian Jira Align < 10.109.2 - Incorrect Default Permissions
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.
CWE-276 Oct 14, 2022
CVE-2022-36802 4.9 MEDIUM EPSS 0.00
Atlassian Jira Align < 10.109.2 - SSRF
The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.
CWE-918 Oct 14, 2022