All CVEs — page 133 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is an Improper Input Validation vulnerability in Adobe Experience Manager Forms JEE that allows high-privileged attackers to execute arbitrary code. This matters because it can lead to full system compromise without user interaction.
This flaw allows an attacker to upload arbitrary files outside the workspace by manipulating the file_path parameter in confluence_upload_attachment, potentially leading to unauthorized access to server-readable files.
This flaw allows an attacker to read arbitrary local files and attach them to a Jira issue by exploiting the MCP Atlassian server prior to version 0.22.0, leading to potential data exfiltration.
The flaw allows network callers to perform operations with the operator account's permissions via the HTTP MCP endpoint without proper authentication, posing a critical risk.
The flaw allows unauthenticated network callers to read files accessible to the MCP process and upload them to Jira or Confluence, posing a significant security risk.
This vulnerability allows an attacker to execute arbitrary code in the context of the current user, leading to potential full system compromise.