atlassian

468 tracked vulnerabilities.

CVE-2021-26082 MEDIUM
Atlassian Jira Server and Data Center < 8.5.14, 8.6.0-8.13.6 - Stored Cross-Site Scripting via XML Export
Jul 20, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-26081 MEDIUM
Atlassian Jira Server/Jira Data Center <8.5.14, <8.6.0-8.13.6, <8.1...
Jul 20, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-26080 MEDIUM
Jira Server and Data Center < 8.5.14, 8.6.0-8.13.6, 8.14.0-8.16.1 - Cross-Site Scripting in EditworkflowScheme.jspa
Jun 07, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-26079 MEDIUM
Jira Server and Data Center < 8.5.15 and 8.6.0-8.13.7 - Cross-Site Scripting in CardLayoutConfigTable
Jun 07, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-26078 MEDIUM
Atlassian Jira < 8.5.14, 8.6.0-8.13.6, 8.14.0-8.16.0 - Cross-Site Scripting in Number Range Searcher
Jun 07, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-26077 HIGH
Atlassian Connect Spring Boot 1.1.0-2.1.3 and 2.1.4-2.1.5 - Improper Authentication via Context JWT Acceptance
May 10, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-26074 MEDIUM
Atlassian Connect Spring Boot 1.1.0-2.1.2 - Improper Authentication via Context JWT Acceptance
Apr 16, 2021
CVSS 6.5
EPSS 0.00
CVE-2021-26073 HIGH
atlassian-connect-express 3.0.2-6.5.9 - Improper Authentication via Context JWT Acceptance
Apr 16, 2021
CVSS 7.7
EPSS 0.00
CVE-2021-26076 LOW
Jira Server/Data Center <8.5.12, <8.6.0-<8.13.4, <8.14.0-<8.15.0 - ...
Apr 15, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-26075 MEDIUM
Jira Server/Data Center <8.5.12, 8.6.0-8.13.4 Info Disclosure via AttachTemporaryFile
Apr 15, 2021
CVSS 4.3
EPSS 0.00
CVE-2021-26072 MEDIUM NUCLEI
Confluence Server and Data Center < 5.8.6 - Server-Side Request Forgery via WidgetConnector
Apr 01, 2021
CVSS 4.3
EPSS 0.18
CVE-2021-26071 LOW
Jira Server/Data Center <8.5.13, 8.6.0-8.13.5 - CSRF via SetFeatureEnabled.jspa
Apr 01, 2021
CVSS 3.5
EPSS 0.00
CVE-2021-26070 HIGH
Atlassian Jira Server/Data Center <8.13.3, 8.14.0-8.14.1 Broken Authentication
Mar 22, 2021
CVSS 7.2
EPSS 0.00
CVE-2021-26069 MEDIUM
Atlassian Jira Server/Data Center <8.5.11, 8.6.0-8.13.2, 8.14.0-8.14.9 - Unauthenticated Info Disclosure via API
Mar 22, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-26068 HIGH
Atlassian Jira Server for Slack 0.0.3-2.0.14 - Remote Code Execution via Template Injection
Feb 22, 2021
CVSS 8.8
EPSS 0.04
CVE-2021-26067 MEDIUM
Atlassian Bamboo < 7.2.2 - Unauthenticated Sensitive Data Exposure via Chart Endpoint
Jan 28, 2021
CVSS 5.3
EPSS 0.01
CVE-2020-36290 MEDIUM
Confluence Data Center and Server < 7.4.5, 7.5.0-7.6.3, 7.7.0-7.7.4 - Stored Cross-Site Scripting in Livesearch Macro
Jul 26, 2022
CVSS 5.4
EPSS 0.00
CVE-2020-18685 CRITICAL
Floodlight < 1.2 - Improper Input Validation in StaticFlowEntryPusherResource
Sep 30, 2021
CVSS 9.8
EPSS 0.00
CVE-2020-18684 CRITICAL
Floodlight < 1.2 - Integer Overflow via Priority or Port Number
Sep 30, 2021
CVSS 9.8
EPSS 0.00
CVE-2020-18683 CRITICAL
Floodlight < 1.2 - Improper Input Validation in StaticFlowEntryPusherResource
Sep 30, 2021
CVSS 9.8
EPSS 0.00
CVE-2020-36239 CRITICAL
Atlassian Jira Data Center < 8.5.16 - Missing Authorization
Jul 29, 2021
CVSS 9.8
EPSS 0.16
CVE-2020-36289 MEDIUM NUCLEI
Atlassian Data Center < 8.5.13 - Incorrect Authorization
May 12, 2021
CVSS 5.3
EPSS 0.92
CVE-2020-29445 MEDIUM
Confluence Server <7.4.8 & <7.5.0-7.11.0 - SSRF
May 07, 2021
CVSS 4.3
EPSS 0.00
CVE-2020-29444 MEDIUM
Confluence Data Center and Server < 7.11.0 - Stored Cross-Site Scripting in Team Calendar Admin Settings
May 07, 2021
CVSS 5.4
EPSS 0.00
CVE-2020-36288 MEDIUM
Jira Server and Data Center < 8.5.12, 8.6.0-8.13.4 - DOM Cross-Site Scripting via Parameter Pollution
Apr 15, 2021
CVSS 6.1
EPSS 0.01