Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.3Atlassian

Medium [CVE-2025-22178] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVE-2025-22178
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22177] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

CVE-2025-22177
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22176] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

CVE-2025-22176
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22175] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

CVE-2025-22175
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22174] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVE-2025-22174
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22173] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

CVE-2025-22173
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22172] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

CVE-2025-22172
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22171] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

CVE-2025-22171
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22170] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

CVE-2025-22170
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22169] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.

CVE-2025-22169
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22168] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

CVE-2025-22168
Jira
Oct 22, 2025
High7.3Atlassian

High [CVE-2025-22165] This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac.

This Medium severity ACE (Arbitrary Code Execution) vulnerability was introduced in version 4.2.8 of Sourcetree for Mac. This ACE (Arbitrary Code Execution) vulnerability, with a CVSS Score of 5.9, allows a locally authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac users upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes. You can download the latest version of Sourcetree for Mac from the download center. This vulnerability was found through the Atlassian Bug Bounty Program by Karol Mazurek (AFINE).

CVE-2025-22165
Unclassified
Jul 24, 2025
High8.8Atlassian

High [CVE-2025-22157] Jira Service Management: This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0…

This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and 10.5.0 of Jira Core Data Center and Server This PrivEsc (Privilege Escalation) vulnerability, with a CVSS Score of 7.2, allows an attacker to perform actions as a higher-privileged user. Jira Core Data Center 10.3: Upgrade to a release greater than or equal to 10.3.5 See the release notes. This vulnerability was reported via our Atlassian (Internal) program. Affected product named by the advisory: Jira Service Management.

CVE-2025-22157
Jira
May 20, 2025
Medium4.3Atlassian

Medium [CVE-2019-15002] Jira: exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0.

An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require a CSRF token. As a result, an attacker can log a user into the system under an unexpected account.

CVE-2019-15002
Jira
Feb 11, 2025
Medium6.4Atlassian

Medium [CVE-2024-21703] This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and…

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with a CVSS Score of 6.4 allows an authenticated attacker of the Windows host to read sensitive information about the Confluence Data Center configuration which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to the latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Confluence Data Center and Server 7.19: Upgrade to a release greater than or equal to 7.19.18 See the release notes ( ). This vulnerability was reported via our Atlassian Bug Bounty Program by Chris Elliot.

CVE-2024-21703
Confluence
Nov 27, 2024
High8.1Atlassian

High [CVE-2024-21687] Confluence: This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of…

This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files already stored locally on the server which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires no user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes ( ). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence.

CVE-2024-21687
ConfluenceBamboo / Crowd / Fisheye
Jul 16, 2024
High8.7Atlassian

High [CVE-2024-21686] Confluence Data Center: This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server.

This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes ( ). This vulnerability was reported via our Bug Bounty program.

CVE-2024-21686
Confluence
Jul 16, 2024
High8.8Atlassian

High [CVE-2024-21683] This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes You can download the latest version of Confluence Data Center and Server from the download center. This vulnerability was found internally.

CVE-2024-21683
Confluence
May 21, 2024
High8.8Atlassian

High [CVE-2024-21677] Confluence Data Center: This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center.

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version and that Confluence Server customers upgrade to the latest 8.5.x LTS version. This vulnerability was reported via our Bug Bounty program.

CVE-2024-21677
Confluence
Mar 19, 2024
High7.2Atlassian

High [CVE-2024-21682] Confluence: This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions).

This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network. This Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions See the release notes ( ). You can download the latest version of Assets Discovery from the Atlassian Marketplace ( ). This vulnerability was reported via our Penetration Testing program. Affected products named by the advisory: Confluence.

CVE-2024-21682
ConfluenceJira
Feb 20, 2024