Known vulnerabilities in Jira Software Data Center

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 152
Public exploits: 27
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Jira Software Data Center Jira Software Data Center is affected by 152 known vulnerabilities: 3 critical, 16 high, 117 medium, 16 low Critical High Medium Low

Vulnerabilities (152)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144403 - Improper Authentication
CVE-2026-21582
CWE-287 High
No
No
9.12.38, 10.3.24, 11.3.10 19.08.2026 SB20260819150
#VU139083 - Interpretation Conflict
CVE-2026-6322
CWE-436 Medium
No
No
10.3.23, 11.3.1 22.07.2026 SB2026072227
SB2026072231
SB2026072232
and 12 more
#VU139082 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-6321
CWE-22 Medium
No
No
10.3.23, 11.3.1 22.07.2026 SB2026072227
SB2026072228
SB2026072229
and 11 more
#VU134926 - Deserialization of Untrusted Data
CVE-2026-42211
CWE-502 High
No
No
10.3.14 19.06.2026 SB2026061979
SB20260619100
SB20260619102
and 1 more
#VU134922 - Resource exhaustion
CVE-2026-34077
CWE-400 Medium
No
No
10.3.14 19.06.2026 SB2026061976
SB2026061989
SB20260619100
and 2 more
#VU134919 - Resource exhaustion
CVE-2026-42342
CWE-400 Medium
No
No
10.3.14 19.06.2026 SB2026061962
SB2026061973
SB20260619100
and 3 more
#VU132348 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-44705
CWE-22 High
Available
No
10.3.23, 11.3.8 27.05.2026 SB2026052717
SB2026072621
SB2026072624
#VU132273 - Incorrect Calculation
CVE-2025-14813
CWE-682 Medium
No
No
10.3.13 25.05.2026 SB2026052529
SB2026052540
SB2026052541
and 17 more
#VU130214 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-42581
CWE-444 Medium
No
No
9.12.28, 10.3.22, 11.3.7 05.05.2026 SB20260505124
SB2026052040
SB20260528254
and 12 more
#VU128414 - Allocation of Resources Without Limits or Throttling
CVE-2026-42198
CWE-770 Medium
No
No
9.12.37, 10.3.23, 11.3.8 28.04.2026 SB20260428236
SB2026052067
SB2026052092
and 23 more
#VU127593 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42044
CWE-1321 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424168
SB2026062221
SB2026062508
and 8 more
#VU126873 - Inefficient Regular Expression Complexity
CVE-2026-27904
CWE-1333 Low
No
No
10.3.22, 11.3.4 22.04.2026 SB20260422244
SB20260423104
SB20260423105
and 15 more
#VU125740 - Improper Certificate Validation
CVE-2026-29145
CWE-295 Low
No
No
9.12.35, 10.3.20, 11.3.4 09.04.2026 SB20260409109
SB20260417131
SB20260422214
and 17 more
#VU125739 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2026-29146
CWE-327 Medium
No
No
9.12.35, 10.3.20, 11.3.4, 11.3.5 09.04.2026 SB20260409109
SB20260417131
SB20260422214
and 28 more
#VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-29063
CWE-1321 Medium
No
No
10.3.23 02.04.2026 SB2026040246
SB2026040612
SB2026040627
and 32 more
#VU124423 - Allocation of Resources Without Limits or Throttling
CVE-2026-33871
CWE-770 Medium
No
No
9.12.28, 10.3.22, 11.3.5 25.03.2026 SB2026032533
SB20260415180
SB20260422237
and 15 more
#VU123598 - Inefficient Regular Expression Complexity
CVE-2025-69873
CWE-1333 Low
No
No
10.3.23, 11.3.7 06.03.2026 SB2026030610
SB2026030633
SB2026033162
and 9 more
#VU70123 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-37601
CWE-94 High
No
No
10.3.22 12.12.2022 SB2022121220
SB2023010419
SB2023011403
and 20 more
#VU70122 - Incorrect Regular Expression
CVE-2022-37599
CWE-185 Medium
No
No
10.3.22 12.12.2022 SB2022121221
SB2023010424
SB2023020920
and 19 more
#VU70121 - Incorrect Regular Expression
CVE-2022-37603
CWE-185 Medium
No
No
10.3.22 12.12.2022 SB2022121221
SB2022121222
SB2023010418
and 29 more


Showing elements 1 - 20 out of 152