Known vulnerabilities in Confluence Data Center - page 2

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 180
Public exploits: 26
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Data Center Confluence Data Center is affected by 180 known vulnerabilities: 2 critical, 21 high, 131 medium, 26 low Critical High Medium Low

Vulnerabilities (180)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139083 - Interpretation Conflict
CVE-2026-6322
CWE-436 Medium
No
No
9.2.22, 10.2.14 22.07.2026 SB2026072227
SB2026072231
SB2026072232
and 12 more
#VU139082 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-6321
CWE-22 Medium
No
No
9.2.22, 10.2.14 22.07.2026 SB2026072227
SB2026072228
SB2026072229
and 11 more
#VU139388 - Improper Access Control
CVE-2026-21577
CWE-284 Low
No
No
9.2.17, 10.2.7 21.07.2026 SB2026072612
#VU139387 - Exposure of sensitive information to an unauthorized actor
CVE-2026-21579
CWE-200 Medium
No
No
9.2.22, 10.2.14 21.07.2026 SB2026072611
#VU134878 - Inefficient Algorithmic Complexity
CVE-2026-27903
CWE-407 Medium
No
No
9.2.21, 10.2.10 18.06.2026 SB2026022345
SB2026061994
SB2026061999
and 3 more
#VU131249 - Use of Uninitialized Resource
CVE-2026-45736
CWE-908 Low
No
No
9.2.5 12.05.2026 SB20260512113
SB2026061995
SB2026062221
and 9 more
#VU131177 - Improper Access Control
CVE-2026-43515
CWE-284 Medium
Available
No
9.2.21, 10.2.13 12.05.2026 SB2026051281
SB2026051592
SB2026060605
and 21 more
#VU131179 - Improper Handling of Case Sensitivity
CVE-2026-43513
CWE-178 Medium
No
No
9.2.21, 10.2.13 12.05.2026 SB2026051281
SB2026051592
SB2026060605
and 19 more
#VU131180 - Improper Authentication
CVE-2026-43512
CWE-287 Medium
Available
No
9.2.21, 10.2.13 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU131182 - Improper input validation
CVE-2026-41293
CWE-20 Medium
No
No
9.2.21, 10.2.13 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU131183 - Resource exhaustion
CVE-2026-41284
CWE-400 Medium
No
No
9.2.21, 10.2.13 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU130210 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-42585
CWE-444 Medium
No
No
9.2.21, 10.2.13 05.05.2026 SB20260505124
SB2026052040
SB20260528254
and 13 more
#VU130208 - Null Byte Interaction Error (Poison Null Byte)
CVE-2026-42579
CWE-626 Medium
No
No
9.2.21, 10.2.13 05.05.2026 SB20260505124
SB2026060936
SB2026060963
and 7 more
#VU130206 - Allocation of Resources Without Limits or Throttling
CVE-2026-42583
CWE-770 Medium
No
No
9.2.22, 10.2.14 05.05.2026 SB20260505124
SB2026052039
SB20260528254
and 8 more
#VU130205 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-42584
CWE-444 Medium
No
No
9.2.21, 10.2.13 05.05.2026 SB20260505124
SB2026052040
SB20260528254
and 13 more
#VU127594 - Permissive List of Allowed Inputs
CVE-2026-42043
CWE-183 Medium
No
No
9.2.22, 10.2.14 24.04.2026 SB20260424169
SB2026061954
SB2026061999
and 10 more
#VU126873 - Inefficient Regular Expression Complexity
CVE-2026-27904
CWE-1333 Low
No
No
9.2.21, 10.2.10 22.04.2026 SB20260422244
SB20260423104
SB20260423105
and 15 more
#VU125803 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-4800
CWE-94 High
No
No
9.2.22, 10.2.14 10.04.2026 SB2026041094
SB20260410101
SB20260410102
and 59 more
#VU125750 - Server-Side Request Forgery (SSRF)
CVE-2025-62718
CWE-918 High
No
No
9.2.22, 10.2.14 10.04.2026 SB2026041001
SB2026050419
SB2026050715
and 29 more
#VU123140 - Inefficient Regular Expression Complexity
CVE-2026-26996
CWE-1333 Medium
No
No
9.2.21, 10.2.10 23.02.2026 SB2026022345
SB2026030633
SB2026032328
and 33 more


Showing elements 21 - 40 out of 180