Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2021-26086 | Atlassian | Jira Server and Data Center | Atlassian Jira Server and Data Center Path Traversal Vulnerability Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint. | 5.3 CISA | 2024-11-12 | 2024-12-03 | Unknown |
| CVE-2023-22527 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Template Injection Vulnerability Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution. | 10.0 CNA | 2024-01-24 | 2024-02-14 | Known |
| CVE-2023-22518 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. | 10.0 CNA | 2023-11-07 | 2023-11-28 | Known |
| CVE-2023-22515 | Atlassian | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence. | 10.0 CNA | 2023-10-05 | 2023-10-13 | Known |
| CVE-2022-36804 | Atlassian | Bitbucket Server and Data Center | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request. | 8.8 CISA | 2022-09-30 | 2022-10-21 | Unknown |
| CVE-2022-26138 | Atlassian | Confluence | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. | 9.8 CISA | 2022-07-29 | 2022-08-19 | Unknown |
| CVE-2022-26134 | Atlassian | Confluence Server/Data Center | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution. | 9.8 CISA | 2022-06-02 | 2022-06-06 | Known |
| CVE-2021-26085 | Atlassian | Confluence Server | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint. | 5.3 CISA | 2022-03-28 | 2022-04-18 | Known |
| CVE-2019-11581 | Atlassian | Jira Server and Data Center | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution. | 9.8 CISA | 2022-03-07 | 2022-09-07 | Unknown |
| CVE-2019-3396 | Atlassian | Confluence Server and Data Server | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2019-11580 | Atlassian | Crowd and Crowd Data Center | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Known |
| CVE-2021-26084 | Atlassian | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code. | 9.8 CISA | 2021-11-03 | 2021-11-17 |
Known
A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
2023 Top Routinely Exploited Vulnerabilities
Russian Military Cyber Actors Target US and Global Critical Infrastructure
Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action
APT40 Advisory: PRC MSS Tradecraft in Action
|
| CVE-2019-3398 | Atlassian | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Path Traversal Vulnerability Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |