Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

240 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.8QNAP

Low [CVE-2023-32973] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later

CVE-2023-32973
QTSQuTS hero
Oct 13, 2023
Low3.5GitLab

Low [CVE-2023-3906] Improper Validation of Specified Type of Input in GitLab

An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

CVE-2023-3906
Unclassified
Sep 29, 2023
Low3.1GitLab

Low [CVE-2023-3979] Incorrect Authorization in GitLab

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVE-2023-3979
Unclassified
Sep 29, 2023
Low3.1QNAP

Low [CVE-2023-34973] QTS: insufficient entropy vulnerability has been reported to affect QNAP operating systems.

An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

CVE-2023-34973
QTSQuTS hero
Aug 24, 2023
Low3.5QNAP

Low [CVE-2023-34972] QTS: cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems.

A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

CVE-2023-34972
QTSQuTS hero
Aug 24, 2023
Low2.7QNAP

Low [CVE-2022-27598] QTS: vulnerability has been reported to affect QNAP operating systems.

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) We have already fixed the vulnerability in the following versions: QTS 5.0.1.2346 build 20230322 and later QuTS hero h5.0.1.2348 build 20230324 and later

CVE-2022-27598
QTSQuTS heroSurveillance (QVR)
Mar 29, 2023
Low3.3Sophos

Low [CVE-2022-4901] Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI

Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.

CVE-2022-4901
Sophos Mobile / Connect
Mar 1, 2023
Low2.7Sophos

Low [CVE-2022-3710] Sophos Firewall: post-auth read-only SQL injection vulnerability

A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3710
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
Low3.0Splunk

Low [CVE-2022-43562] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host…

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape the Host header, which could let a remote authenticated user conduct various attacks against the system, including cross-site scripting and cache poisoning.

CVE-2022-43562
Splunk Enterprise
Nov 4, 2022
Low3.7F5

Low [CVE-2022-41983] On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all…

On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied.

CVE-2022-41983
BIG-IP
Oct 19, 2022
Low2.6Splunk

Low [CVE-2022-37438] In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard

In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and share dashboards using Splunk Web.

CVE-2022-37438
Splunk Enterprise
Aug 16, 2022
Low3.7F5

Low [CVE-2022-33968] In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all…

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, when an LTM monitor or APM SSO is configured on a virtual server, and NTLM challenge-response is in use, undisclosed traffic can cause a buffer over-read. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-33968
BIG-IP
Aug 4, 2022
Low2.3Check Point

Low [CVE-2022-23744] Check Point Endpoint before version E86.50 failed to protect against specific registry change

Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.

CVE-2022-23744
Unclassified
Jul 7, 2022
Low3.1F5

Low [CVE-2022-1389] On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request…

On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site request forgery (CSRF) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This vulnerability allows an attacker to run a limited set of commands: ping, traceroute, and WOM diagnostics. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-1389
BIG-IP
May 5, 2022
Low3.9Sophos

Low [CVE-2021-25266] Intercept X: insecure data storage vulnerability

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

CVE-2021-25266
Intercept X / Central
Apr 27, 2022
Low3.3Sophos

Low [CVE-2022-0652] Sophos UTM: Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions.

Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

CVE-2022-0652
Sophos UTM
Mar 22, 2022
Low3.7Atlassian

Low [CVE-2021-26076] The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from…

The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set with a secure attribute if Jira was configured to use https.

CVE-2021-26076
Jira
Apr 15, 2021
Low3.5Atlassian

Low [CVE-2021-26071] Jira Software: The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version…

The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability.

CVE-2021-26071
Jira
Apr 1, 2021
Low2.3QNAP

Low [CVE-2020-2505] If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages.

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2505
Unclassified
Dec 24, 2020
Low2.0QNAP

Low [CVE-2018-19948] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19948
Unclassified
Sep 11, 2020