Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
55639
Total
4397
Critical
16518
High
16189
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77271 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), … | Sep 22, 2026 |
| CVE-2026-77270 | MEDIUM | 6.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools … | Sep 22, 2026 |
| CVE-2026-77267 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed … | Sep 22, 2026 |
| CVE-2026-77265 | MEDIUM | 5.9 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved … | Sep 22, 2026 |
| CVE-2026-77261 | HIGH | 7.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher … | Sep 22, 2026 |
| CVE-2026-77260 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept … | Sep 22, 2026 |
| CVE-2026-77258 | HIGH | 7.7 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path … | Sep 22, 2026 |
| CVE-2026-77252 | MEDIUM | 6.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace … | Sep 22, 2026 |
| CVE-2026-77251 | UNKNOWN | — | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause … | Sep 22, 2026 |
| CVE-2026-77250 | MEDIUM | 6.1 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing … | Sep 22, 2026 |
| CVE-2026-77244 | CRITICAL | 10.0 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a … | Sep 22, 2026 |
| CVE-2026-77243 | HIGH | 8.8 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools … | Sep 22, 2026 |
| CVE-2026-77242 | HIGH | 7.5 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf checks a hostname's resolved addresses, but … | Sep 22, 2026 |
| CVE-2026-75728 | CRITICAL | 9.1 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … | Sep 22, 2026 |
| CVE-2026-75723 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … | Sep 22, 2026 |
| CVE-2026-75721 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-75703 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-75699 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-73369 | CRITICAL | 10.0 | Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in … | Sep 22, 2026 |
| CVE-2026-43643 | HIGH | 7.5 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify … | Sep 22, 2026 |
| CVE-2026-43642 | HIGH | 8.1 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to … | Sep 22, 2026 |
| CVE-2026-43641 | CRITICAL | 9.8 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to … | Sep 22, 2026 |
| CVE-2026-18626 | UNKNOWN | — | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, … | Sep 22, 2026 |
| CVE-2026-18462 | UNKNOWN | — | Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 … | Sep 22, 2026 |
| CVE-2026-18461 | UNKNOWN | — | Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, … | Sep 22, 2026 |