Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical10.0QNAP

Critical [CVE-2023-34976] Video Station: SQL injection vulnerability has been reported to affect Video Station.

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

CVE-2023-34976
Applications
Oct 13, 2023
Critical9.9F5

Critical [CVE-2023-41373] directory traversal vulnerability exists in the BIG-IP Configuration Utility that may

A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41373
BIG-IP
Oct 10, 2023
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2023-22515] Confluence Data Center: Atlassian has been made aware of an issue reported by a handful of customers where external attackers

Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22515
Confluence
Oct 4, 2023
CriticalCommvault Exploited CISA KEV

Critical [CVE-2023-4863] Libwebp Vulnerability

CVE.Org link: CVE-2023-4863 Save as PDF

CVE-2023-4863
Unclassified
Oct 4, 2023
Critical10.0Ivanti Exploited CISA KEV

Critical [CVE-2023-35078] Endpoint Manager Mobile: authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication. Affected products named by the advisory: Endpoint Manager Mobile; endpoint_manager_mobile.

CVE-2023-35078
Endpoint Manager
Jul 25, 2023
CriticalCommvault

Critical Volt Typhoon Advisory

Save as PDF Impacted Products With the recent announcement of the Volt Typhoon cyber campaign, our team has conducted a thorough security assessment of Commvault and Commvault Cloud services and have found no impact to the security, privacy, or integrity of your data backups. Resolution We also recommend you to check your Commvault and Commvault Cloud environment to ensure security controls such as the following are active:MFA is properly configured and up to dateDual authorization workflows are in place for backup and restore operationsCompliance locks are enabled for services, apps, and backup destinationsAdditionally, for customers looking for an extra layer of protection, we encourage you to evaluate ThreatWise, capable of surfacing zero-day and unknown threats in production environments. On this page

Commvault Cloud (Metallic)
May 26, 2023
Critical9.6Check Point

Critical [CVE-2023-28131] vulnerability in the expo.io framework

A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc).

CVE-2023-28131
Unclassified
Apr 24, 2023
Critical9.6pfSense

Critical [CVE-2020-21487] Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

CVE-2020-21487
Unclassified
Apr 4, 2023
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2023-1671] pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CVE-2023-1671
Unclassified
Apr 4, 2023
Critical9.8pfSense

Critical [CVE-2023-27100] Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1…

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

CVE-2023-27100
pfSense PluspfSense CE
Mar 22, 2023
Critical9.8Ubiquiti

Critical [CVE-2023-24104] UniFi: Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

CVE-2023-24104
UniFi Network / OS
Feb 23, 2023
Critical9.1Atlassian

Critical [CVE-2023-22501] authentication vulnerability was discovered in Jira Service Management Server and Data Center which

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: - If the attacker is included on Jira issues or requests with these users, or - If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.

CVE-2023-22501
Jira
Feb 1, 2023
Critical9.8QNAP

Critical [CVE-2022-27596] QTS: vulnerability has been reported to affect QNAP device running QuTS hero, QTS.

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later

CVE-2022-27596
QTSQuTS hero
Jan 30, 2023
Critical9.8Atlassian

Critical [CVE-2022-43781] Bitbucket: There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVE-2022-43781
Bitbucket
Nov 17, 2022
Critical9.8Sophos

Critical [CVE-2022-3980] Sophos Mobile: XML External Entity (XEE) vulnerability

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

CVE-2022-3980
Sophos Mobile / Connect
Nov 16, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-3236] Sophos Firewall: code injection vulnerability in the User Portal and Webadmin

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-3236
Sophos Firewall (XGS/SFOS)
Sep 23, 2022
Critical10.0QNAP Exploited CISA KEV

Critical [CVE-2022-27593] QTS: externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-27593
QTSApplications
Sep 8, 2022
Critical9.8pfSense

Critical [CVE-2022-31814] pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

CVE-2022-31814
Unclassified
Sep 5, 2022
Critical9.8Check Point

Critical [CVE-2022-23747] In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

CVE-2022-23747
Unclassified
Aug 17, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26138] The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the…

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-26138
Confluence
Jul 20, 2022