Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

2,234

Total CVEs

1,589

CISA KEV

41

Known Exploits

8.8

Avg CVSS Score

Severity Distribution

CRITICAL 8
HIGH 1599
MEDIUM 7
INFO 620

Showing 13 of 13 CVEs matching "Atlassian" · HIGH · CISA KEV

CVE-2021-26086KEV
High

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

AtlassianEPSS 94.2%
CVE-2023-22527KEV
High

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

AtlassianCVSS 9.8EPSS 94.4%
Exploit
CVE-2023-22518KEV
High

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

AtlassianEPSS 94.4%
CVE-2023-22515KEV
High

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

AtlassianEPSS 94.3%
CVE-2022-36804KEV
High

Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.

AtlassianEPSS 94.4%
CVE-2022-26138KEV
High

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

AtlassianEPSS 94.3%
CVE-2022-26134KEV
High

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

AtlassianCVSS 9.8EPSS 94.4%
Exploit
CVE-2021-26085KEV
High

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

AtlassianEPSS 94.0%
CVE-2019-11581KEV
High

Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.

AtlassianEPSS 94.4%
CVE-2021-26084KEV
High

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

AtlassianEPSS 94.4%
CVE-2019-11580KEV
High

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

AtlassianEPSS 94.4%
CVE-2019-3398KEV
High

Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.

AtlassianEPSS 93.9%
CVE-2019-3396KEV
High

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

AtlassianCVSS 9.8EPSS 94.5%
Exploit