Known vulnerabilities in Confluence Server 7.3.5 - page 2

Vendor: Atlassian
Version: 7.3.5
Software CPE: cpe:2.3:a:atlassian:atlassian_confluence_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 47
Public exploits: 6
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Confluence Server version 7.3.5 Confluence Server 7.3.5 is affected by 47 vulnerabilities: 1 critical, 8 high, 28 medium, 10 low Critical High Medium Low

Vulnerabilities (47)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU94796 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-21686
CWE-79 Low
No
No
7.19.22, 8.5.9, 8.9.1 28.07.2024 SB2024072804
#VU89803 - Improper input validation
CVE-2024-21683
CWE-20 Medium
Public exploit available
No
7.19.22, 8.5.9, 8.9.1 24.05.2024 SB2024052424
#VU89801 - Server-Side Request Forgery (SSRF)
CVE-2024-22262
CWE-918 Medium
No
No
7.19.24, 8.5.11, 8.9.3 24.05.2024 SB2024052420
SB2024052423
SB2024052708
and 76 more
#VU87744 - Out-of-bounds write
CVE-2024-29133
CWE-787 High
No
No
7.19.23, 8.5.9, 8.9.1 22.03.2024 SB2024032169
SB2024032283
SB20240417122
and 40 more
#VU87706 - Out-of-bounds write
CVE-2024-29131
CWE-787 High
No
No
7.19.23, 8.5.9, 8.9.1 21.03.2024 SB2024032169
SB2024032283
SB20240417122
and 36 more
#VU87614 - Server-Side Request Forgery (SSRF)
CVE-2024-22259
CWE-918 Medium
No
No
7.19.23, 8.5.9, 8.9.1 19.03.2024 SB2024031918
SB2024040207
SB2024041660
and 39 more
#VU87607 - Improper Access Control
CVE-2024-22257
CWE-284 Medium
No
No
7.19.22, 8.5.9, 8.9.1 19.03.2024 SB2024031915
SB2024041659
SB2024041660
and 26 more
#VU87510 - Improper input validation
CVE-2024-24549
CWE-20 Medium
Public exploit available
No
7.19.22, 8.5.9, 8.9.1 13.03.2024 SB2024031386
SB2024031879
SB2024031880
and 64 more
#VU87509 - Resource exhaustion
CVE-2024-23672
CWE-400 Medium
No
No
7.19.22, 8.5.9, 8.9.1 13.03.2024 SB2024031386
SB2024032821
SB2024032824
and 49 more
#VU86983 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-1597
CWE-89 High
No
No
7.19.21, 8.5.8, 8.9.0 04.03.2024 SB2024030405
SB2024030406
SB2024030427
and 47 more
#VU86859 - Improper Access Control
CVE-2023-45859
CWE-284 Medium
No
No
7.19.22, 8.5.9, 8.9.0 27.02.2024 SB2024022773
SB2024052426
SB2024121109
#VU86695 - Server-Side Request Forgery (SSRF)
CVE-2024-22243
CWE-918 Medium
Public exploit available
No
7.19.23, 8.5.9, 8.9.1 21.02.2024 SB2024022140
SB2024030406
SB2024030529
and 45 more
#VU85439 - Improper input validation
CVE-2024-21672
CWE-20 High
No
No
7.19.18, 8.5.5, 8.7.2 16.01.2024 SB2024011640
#VU82143 - Improper input validation
CVE-2023-22025
CWE-20 Low
No
No
7.19.25, 8.5.12 17.10.2023 SB2023101797
SB2023101798
SB2023101905
and 36 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Public exploit available
Exploited
7.19.16, 7.19.17, 8.3.4, 8.4.5, 8.5.3, 8.5.4, 8.6.1, 8.6.2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 652 more
#VU80762 - Resource exhaustion
CVE-2023-41835
CWE-400 Medium
No
No
7.19.18, 8.5.5, 8.7.2, 8.8.0 13.09.2023 SB2023091364
SB2023110308
SB2023113020
and 7 more
#VU77778 - Improper input validation
CVE-2022-29546
CWE-20 Low
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 28.06.2023 SB2022050443
SB20230719104
SB20231018117
and 10 more
#VU77777 - Improper input validation
CVE-2022-28366
CWE-20 Low
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 28.06.2023 SB2022042155
SB2023112475
SB2023121271
and 7 more
#VU65486 - Improper input validation
CVE-2022-24839
CWE-20 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 20.07.2022 SB2022072038
SB2022102803
SB2022102807
and 31 more
#VU48979 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-25649
CWE-611 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 03.12.2020 SB2020121510
SB2021020321
SB2021042112
and 68 more


Showing elements 21 - 40 out of 47