Known vulnerabilities in Confluence Data Center - page 4

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 180
Public exploits: 26
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Data Center Confluence Data Center is affected by 180 known vulnerabilities: 2 critical, 21 high, 131 medium, 26 low Critical High Medium Low

Vulnerabilities (180)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
9.2.19, 10.2.10 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 32 more
#VU124423 - Allocation of Resources Without Limits or Throttling
CVE-2026-33871
CWE-770 Medium
No
No
9.2.19, 10.2.10 25.03.2026 SB2026032533
SB20260415180
SB20260422237
and 15 more
#VU122099 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-24842
CWE-22 Medium
Available
No
9.2.19, 10.2.10 28.01.2026 SB2026012845
SB20260202129
SB2026020564
and 8 more
#VU121937 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-53689
CWE-611 Medium
No
No
9.2.11, 10.1.0 22.01.2026 SB2026012219
SB2026012277
#VU121671 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-23950
CWE-362 Medium
Available
No
9.2.19, 10.2.10 20.01.2026 SB2026012003
SB20260202129
SB2026020564
and 9 more
#VU121640 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-23745
CWE-22 Medium
Available
No
9.2.19, 10.2.10 19.01.2026 SB2026011930
SB20260202129
SB2026020564
and 11 more
#VU119401 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-64756
CWE-78 Medium
No
No
9.0.2, 9.2.15, 10.2.7 09.12.2025 SB2025120922
SB2025120932
SB20251210178
and 18 more
#VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-59343
CWE-22 High
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1 17.10.2025 SB2025101702
SB2025101703
SB2025101704
and 22 more
#VU115573 - Protection Mechanism Failure
CVE-2025-41249
CWE-693 Medium
No
No
9.2.14, 10.2.3 16.09.2025 SB20250916314
SB2025100741
SB20251008143
and 62 more
#VU114385 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2025-54988
CWE-611 Medium
Available
No
8.5.31, 9.2.13, 10.2.2 22.08.2025 SB2025082219
SB2025083007
SB2025083008
and 31 more
#VU112166 - Improper Authentication
CVE-2025-49146
CWE-287 High
No
No
9.2.11 04.07.2025 SB2025070405
SB2025070406
SB2025070708
and 13 more
#VU111162 - Resource exhaustion
CVE-2025-48976
CWE-400 Medium
Available
No
9.2.7, 9.5.3 16.06.2025 SB2025061634
SB2025061635
SB2025061927
and 156 more
#VU106282 - Improper Link Resolution Before File Access ('Link Following')
CVE-2024-12905
CWE-59 High
No
No
8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2 31.03.2025 SB2025033140
SB2025033150
SB2025033151
and 15 more
#VU95816 - Server-Side Request Forgery (SSRF)
CVE-2024-29415
CWE-918 Medium
Available
No
8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2 13.08.2024 SB2024081345
SB2024082612
SB2024082760
and 14 more
#VU78932 - Incorrect Regular Expression
CVE-2022-25883
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.2.3 03.08.2023 SB2023080361
SB2023080362
SB2023081514
and 73 more
#VU73969 - Incorrect Regular Expression
CVE-2022-25927
CWE-185 Medium
No
No
9.2.14, 10.2.3 23.03.2023 SB2023032313
SB2023032315
SB2023032710
and 19 more
#VU70123 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-37601
CWE-94 High
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121220
SB2023010419
SB2023011403
and 20 more
#VU70122 - Incorrect Regular Expression
CVE-2022-37599
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121221
SB2023010424
SB2023020920
and 19 more
#VU70121 - Incorrect Regular Expression
CVE-2022-37603
CWE-185 Medium
No
No
9.2.1, 9.4.0, 9.5.1, 10.0.2 12.12.2022 SB2022121221
SB2022121222
SB2023010418
and 29 more
#VU52985 - Incorrect Regular Expression
CVE-2020-28469
CWE-185 Medium
No
No
9.2.13, 10.2.2 10.05.2021 SB2021051002
SB2021051004
SB2021072625
and 26 more


Showing elements 61 - 80 out of 180