Known vulnerabilities in Jira Software Data Center - page 2

Vendor: Atlassian
Software CPE: cpe:2.3:a:atlassian:jira_data_center:*:*:*:*:*:*:*:*
Total vulnerabilities: 152
Public exploits: 27
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Jira Software Data Center Jira Software Data Center is affected by 152 known vulnerabilities: 3 critical, 16 high, 117 medium, 16 low Critical High Medium Low

Vulnerabilities (152)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134878 - Inefficient Algorithmic Complexity
CVE-2026-27903
CWE-407 Medium
No
No
10.3.22, 11.3.4 18.06.2026 SB2026022345
SB2026061994
SB2026061999
and 3 more
#VU132949 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-44495
CWE-1321 Medium
No
No
10.3.22, 11.3.7 29.05.2026 SB20260424169
SB2026061999
SB20260619101
and 10 more
#VU131921 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-40175
CWE-113 Medium
No
No
10.3.22, 11.3.7 20.05.2026 SB2026052045
SB2026052051
SB2026052052
and 21 more
#VU131177 - Improper Access Control
CVE-2026-43515
CWE-284 Medium
Available
No
9.12.36, 10.3.22, 11.3.7 12.05.2026 SB2026051281
SB2026051592
SB2026060605
and 21 more
#VU131179 - Improper Handling of Case Sensitivity
CVE-2026-43513
CWE-178 Medium
No
No
9.12.36, 10.3.22, 11.3.7 12.05.2026 SB2026051281
SB2026051592
SB2026060605
and 19 more
#VU131180 - Improper Authentication
CVE-2026-43512
CWE-287 Medium
Available
No
9.12.36, 10.3.22, 11.3.7 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU131182 - Improper input validation
CVE-2026-41293
CWE-20 Medium
No
No
9.12.36, 10.3.22, 11.3.7 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU131183 - Resource exhaustion
CVE-2026-41284
CWE-400 Medium
No
No
9.12.36, 10.3.22, 11.3.7 12.05.2026 SB2026051281
SB2026051592
SB2026052607
and 21 more
#VU130210 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-42585
CWE-444 Medium
No
No
9.12.28, 10.3.22, 11.3.7 05.05.2026 SB20260505124
SB2026052040
SB20260528254
and 13 more
#VU130205 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-42584
CWE-444 Medium
No
No
9.12.28, 10.3.22, 11.3.7 05.05.2026 SB20260505124
SB2026052040
SB20260528254
and 13 more
#VU127606 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2026-42035
CWE-113 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424169
SB2026061912
SB2026061913
and 15 more
#VU127603 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42033
CWE-1321 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424169
SB2026061954
SB2026061992
and 11 more
#VU127599 - Improper Access Control
CVE-2026-42038
CWE-284 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424169
SB2026061992
SB2026061993
and 9 more
#VU127594 - Permissive List of Allowed Inputs
CVE-2026-42043
CWE-183 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424169
SB2026061954
SB2026061999
and 10 more
#VU127592 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2026-42264
CWE-1321 Medium
No
No
10.3.22, 11.3.7 24.04.2026 SB20260424168
SB2026061999
SB20260619101
and 9 more
#VU125750 - Server-Side Request Forgery (SSRF)
CVE-2025-62718
CWE-918 High
No
No
10.3.22, 11.3.7 10.04.2026 SB2026041001
SB2026050419
SB2026050715
and 29 more
#VU125745 - Information Exposure Through Log Files
CVE-2026-34487
CWE-532 Medium
No
No
9.12.35, 10.3.20, 11.3.5 09.04.2026 SB20260409110
SB20260417131
SB20260422214
and 20 more
#VU125746 - Protection Mechanism Failure
CVE-2026-34486
CWE-693 Medium
No
Exploited
11.3.5 09.04.2026 SB20260409110
SB20260417131
SB20260422214
and 14 more
#VU124422 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-33870
CWE-444 Medium
Available
No
9.12.28, 10.3.22, 11.3.5 25.03.2026 SB2026032533
SB20260415180
SB2026042043
and 20 more
#VU76185 - Incorrect Regular Expression
CVE-2021-3803
CWE-185 Medium
No
No
10.3.22 16.05.2023 SB2021091716
SB2023051651
SB2023053029
and 12 more


Showing elements 21 - 40 out of 152