Known vulnerabilities in Confluence Data Center - page 9

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:confluence_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 180
Public exploits: 26
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Confluence Data Center Confluence Data Center is affected by 180 known vulnerabilities: 2 critical, 21 high, 131 medium, 26 low Critical High Medium Low

Vulnerabilities (180)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83896 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22522
CWE-94 High
No
No
7.19.17, 8.4.5, 8.5.4, 8.6.2, 8.7.1 06.12.2023 SB2023120608
#VU82592 - Improper Authorization
CVE-2023-22518
CWE-285 High
Available
Exploited
7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 31.10.2023 SB2023103144
#VU81803 - Exposed Dangerous Method or Function
CVE-2023-42794
CWE-749 Medium
No
No
7.19.16, 8.5.3, 8.6.1 10.10.2023 SB2023101084
SB2023101286
SB2023111528
and 22 more
#VU81728 - Resource exhaustion
CVE-2023-44487
CWE-400 High
Available
Exploited
7.19.16, 7.19.17, 8.3.4, 8.4.5, 8.5.3, 8.5.4, 8.6.1, 8.6.2, 8.7.1 10.10.2023 SB2023101023
SB2023101024
SB2023101037
and 650 more
#VU81631 - Improper Authentication
CVE-2023-22515
CWE-287 Critical
Available
Exploited
8.3.3, 8.4.3, 8.5.2 05.10.2023 SB2023100515
#VU81102 - Resource Management Errors
CVE-2023-22512
CWE-399 Medium
No
No
7.19.14, 8.5.1 25.09.2023 SB2023092534
#VU78553 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22505
CWE-94 Low
No
No
8.3.2, 8.4.0 24.07.2023 SB2023072414
#VU78551 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-22508
CWE-94 Medium
No
No
7.19.8, 8.2.0 24.07.2023 SB2023072410
#VU77777 - Improper input validation
CVE-2022-28366
CWE-20 Low
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2, 8.7.1 28.06.2023 SB2022042155
SB2023112475
SB2023121271
and 7 more
#VU76417 - Allocation of Resources Without Limits or Throttling
CVE-2023-28709
CWE-770 Medium
No
No
7.13.19, 7.19.11, 8.4.1 22.05.2023 SB2023052235
SB2023053003
SB2023053052
and 35 more
#VU70666 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-45143
CWE-94 Medium
No
No
7.13.15, 7.19.16, 8.1.1, 8.2.0 03.01.2023 SB2023010329
SB2023012516
SB2023012606
and 34 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
7.13.18, 7.19.10, 8.3.1, 8.4.5, 8.5.4, 8.6.2, 8.7.1, 9.2.19, 10.2.10 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
7.19.16 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU68827 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42890
CWE-94 Low
No
No
7.19.16 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 34 more
#VU68826 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-41704
CWE-94 High
No
No
7.19.16 30.10.2022 SB2022103004
SB2022103009
SB2023030742
and 14 more
#VU67585 - Server-Side Request Forgery (SSRF)
CVE-2022-40146
CWE-918 Medium
Available
No
7.19.16 22.09.2022 SB2022092232
SB2023011763
SB2023011838
and 21 more
#VU66555 - Deserialization of Untrusted Data
CVE-2022-26133
CWE-502 High
Available
No
7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 17.08.2022 SB2022072917
#VU65892 - Insufficient Verification of Data Authenticity
CVE-2022-26137
CWE-345 Medium
No
No
7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 29.07.2022 SB2022072917
#VU65891 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-26136
CWE-79 Low
No
No
7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 29.07.2022 SB2022072917
#VU65486 - Improper input validation
CVE-2022-24839
CWE-20 Medium
No
No
7.19.17, 8.3.4, 8.4.5, 8.5.4, 8.6.1, 8.6.2, 8.7.1 20.07.2022 SB2022072038
SB2022102803
SB2022102807
and 31 more


Showing elements 161 - 180 out of 180