Complete feed
No mitigation yet
No fix, workaround or mitigation extracted yet
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2025-22178] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.
Medium [CVE-2025-22177] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.
Medium [CVE-2025-22176] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.
Medium [CVE-2025-22175] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.
Medium [CVE-2025-22174] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.
Medium [CVE-2025-22173] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.
Medium [CVE-2025-22172] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.
Medium [CVE-2025-22171] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.
Medium [CVE-2025-22170] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.
Medium [CVE-2025-22169] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.
Medium [CVE-2025-22168] Jira: Jira Align is vulnerable to an authorization issue.
Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.
Medium [CVE-2019-15002] Jira: exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0.
An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.
Medium [CVE-2024-21703] This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and…
This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 See the release notes ( ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.
Medium [CVE-2023-22504] Affected versions of Atlassian Confluence Server
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.