CVE-2023-22518
- EPSS 100%
- Veröffentlicht 31.10.2023 15:15:08
- Zuletzt bearbeitet 24.10.2025 13:38:59
All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account....
CVE-2023-22515
- EPSS 99.16%
- Veröffentlicht 04.10.2023 14:15:10
- Zuletzt bearbeitet 25.03.2026 17:40:00
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Conf...
CVE-2023-22508
- EPSS 2.17%
- Veröffentlicht 18.07.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:57
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated...
CVE-2023-22505
- EPSS 2.06%
- Veröffentlicht 18.07.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:44:57
This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22505 was introduced in version 8.0.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8, allows an authenticated ...
CVE-2023-22503
- EPSS 0.79%
- Veröffentlicht 01.05.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:44:56
Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview ...
CVE-2022-42978
- EPSS 0.8%
- Veröffentlicht 15.11.2022 01:15:13
- Zuletzt bearbeitet 30.04.2025 18:15:35
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
CVE-2022-42977
- EPSS 0.96%
- Veröffentlicht 15.11.2022 01:15:13
- Zuletzt bearbeitet 30.04.2025 19:15:52
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in the application, and export it. During export, the HTTP request has a fileName parameter that accepts any file on the system (e.g....
CVE-2020-36290
- EPSS 0.66%
- Veröffentlicht 26.07.2022 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:13
The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or Ja...
CVE-2022-26137
- EPSS 2.2%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security...
CVE-2022-26136
- EPSS 5.02%
- Veröffentlicht 20.07.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:30
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulner...