Known vulnerabilities in Confluence Server - page 5

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:atlassian_confluence_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 117
Public exploits: 16
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Server Confluence Server is affected by 117 known vulnerabilities: 2 critical, 17 high, 74 medium, 24 low Critical High Medium Low

Vulnerabilities (117)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU85439 - Improper input validation
CVE-2024-21672
CWE-20 High
No
No
7.19.18, 8.5.5, 8.7.2 16.01.2024 SB2024011640
#VU85434 - Improper input validation
CVE-2023-22526
CWE-20 Medium
No
No
7.19.17, 8.5.5, 8.7.2 16.01.2024 SB2024011640
#VU85413 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22527
CWE-94 Critical
Available
Exploited
8.5.4 16.01.2024 SB2024011603
#VU83896 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22522
CWE-94 High
No
No
7.19.17, 8.4.5, 8.5.4 06.12.2023 SB2023120608
#VU82276 - Allocation of Resources Without Limits or Throttling
CVE-2023-5072
CWE-770 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 20.10.2023 SB2023102017
SB2023102018
SB2023113056
and 97 more
#VU81803 - Exposed Dangerous Method or Function
CVE-2023-42794
CWE-749 Medium
No
No
7.19.16, 8.5.3, 8.6.1 10.10.2023 SB2023101084
SB2023101286
SB2023111528
and 22 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
7.19.16, 7.19.17, 8.3.4, 8.4.5, 8.5.3, 8.5.4, 8.6.1, 8.6.2 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU80783 - Incorrect Conversion between Numeric Types
CVE-2023-3635
CWE-681 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 14.09.2023 SB2023091430
SB2023091528
SB2023100937
and 47 more
#VU77778 - Improper input validation
CVE-2022-29546
CWE-20 Low
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 28.06.2023 SB2022050443
SB20230719104
SB20231018117
and 10 more
#VU77777 - Improper input validation
CVE-2022-28366
CWE-20 Low
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 28.06.2023 SB2022042155
SB2023112475
SB2023121271
and 7 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
7.13.19, 7.19.11, 8.4.1 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
7.13.15, 7.19.16, 8.1.1, 8.2.0 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
7.13.18, 7.19.10, 8.3.1, 8.4.5, 8.5.4 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
7.19.16 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU68827 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42890
CWE-94 Low
No
No
7.19.16 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 34 more
#VU68826 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-41704
CWE-94 High
No
No
7.19.16 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 14 more
#VU67585 - Server-Side Request Forgery (SSRF)
CVE-2022-40146
CWE-918 Medium
Available
No
7.19.16 22.09.2022 SB2022092232
SB2023011763
SB2023011838
and 21 more
#VU65499 - Improper input validation
CVE-2021-31684
CWE-20 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 20.07.2022 SB2022072048
SB2022072056
SB2022112850
and 20 more
#VU65486 - Improper input validation
CVE-2022-24839
CWE-20 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2 20.07.2022 SB2022072038
SB2022102803
SB2022102807
and 31 more
#VU48979 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2020-25649
CWE-611 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.2 03.12.2020 SB2020121510
SB2021020321
SB2021042112
and 68 more


Showing elements 81 - 100 out of 117