Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55204
Total
4355
Critical
16406
High
16086
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77257 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass … | Sep 22, 2026 |
| CVE-2026-77256 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh … | Sep 22, 2026 |
| CVE-2026-77255 | HIGH | 8.6 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted … | Sep 22, 2026 |
| CVE-2026-77254 | CRITICAL | 9.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without … | Sep 22, 2026 |
| CVE-2026-77253 | HIGH | 7.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept … | Sep 22, 2026 |
| CVE-2026-77249 | MEDIUM | 5.3 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead … | Sep 22, 2026 |
| CVE-2026-77248 | HIGH | 8.6 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without … | Sep 22, 2026 |
| CVE-2026-77247 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled … | Sep 22, 2026 |
| CVE-2026-77246 | HIGH | 7.4 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts … | Sep 22, 2026 |
| CVE-2026-76194 | MEDIUM | 4.3 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Sep 22, 2026 |
| CVE-2026-76192 | MEDIUM | 5.5 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash … | Sep 22, 2026 |
| CVE-2026-75745 | CRITICAL | 10.0 | Adobe Experience Manager Forms JEE is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current … | Sep 22, 2026 |
| CVE-2026-75744 | HIGH | 8.1 | Adobe Experience Manager Forms JEE is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious … | Sep 22, 2026 |
| CVE-2026-75743 | HIGH | 7.1 | Adobe Experience Manager Forms JEE is affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could … | Sep 22, 2026 |
| CVE-2026-75698 | CRITICAL | 9.3 | Adobe Connect is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, … | Sep 22, 2026 |
| CVE-2026-75697 | CRITICAL | 9.3 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form … | Sep 22, 2026 |
| CVE-2026-75689 | CRITICAL | 9.3 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form … | Sep 22, 2026 |
| CVE-2026-75686 | CRITICAL | 9.3 | Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An … | Sep 22, 2026 |
| CVE-2026-75684 | CRITICAL | 9.3 | Adobe Connect is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form … | Sep 22, 2026 |
| CVE-2026-75682 | CRITICAL | 9.9 | Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code … | Sep 22, 2026 |
| CVE-2026-75676 | HIGH | 7.8 | Bridge is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of … | Sep 22, 2026 |
| CVE-2026-75665 | HIGH | 7.8 | Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of … | Sep 22, 2026 |
| CVE-2026-75663 | HIGH | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this … | Sep 22, 2026 |
| CVE-2026-75658 | HIGH | 7.8 | Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this … | Sep 22, 2026 |
| CVE-2026-75656 | MEDIUM | 5.5 | Bridge is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive … | Sep 22, 2026 |