CVE-2022-26134
- EPSS 100%
- Veröffentlicht 03.06.2022 22:15:07
- Zuletzt bearbeitet 24.10.2025 13:38:30
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1....
CVE-2021-39114
- EPSS 1.66%
- Veröffentlicht 05.04.2022 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:18:36
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions...
CVE-2021-43940
- EPSS 0.33%
- Veröffentlicht 15.02.2022 04:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:02
Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects ins...
CVE-2021-26084
- EPSS 100%
- Veröffentlicht 30.08.2021 07:15:06
- Zuletzt bearbeitet 24.10.2025 13:38:44
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before ...
CVE-2021-26085
- EPSS 99.94%
- Veröffentlicht 03.08.2021 00:15:08
- Zuletzt bearbeitet 24.10.2025 13:38:39
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5....
CVE-2020-29444
- EPSS 0.93%
- Veröffentlicht 07.05.2021 06:15:09
- Zuletzt bearbeitet 12.02.2025 21:15:09
Affected versions of Team Calendar in Confluence Server before 7.11.0 allow attackers to inject arbitrary HTML or Javascript via a Cross Site Scripting Vulnerability in admin global setting parameters.
CVE-2021-26072
- EPSS 38.85%
- Veröffentlicht 01.04.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:55:48
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.
CVE-2020-29448
- EPSS 2.33%
- Veröffentlicht 22.02.2021 21:15:19
- Zuletzt bearbeitet 21.11.2024 05:24:01
The ConfluenceResourceDownloadRewriteRule class in Confluence Server and Confluence Data Center before version 6.13.18, from 6.14.0 before 7.4.6, and from 7.5.0 before 7.8.3 allowed unauthenticated remote attackers to read arbitrary files within WEB-...
CVE-2020-29450
- EPSS 2.21%
- Veröffentlicht 19.01.2021 01:15:14
- Zuletzt bearbeitet 21.11.2024 05:24:01
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the avatar upload feature. The affected versions are before version 7.2.0.
CVE-2020-14175
- EPSS 1.15%
- Veröffentlicht 24.07.2020 07:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:48
Affected versions of Atlassian Confluence Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in user macro parameters. The affected versions are before version 7.4.2, an...