Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5336 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8Splunk

High [CVE-2023-40595] In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.

CVE-2023-40595
Unclassified
Aug 30, 2023
High8.4Splunk

High [CVE-2023-40592] In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can

In Splunk Enterprise versions below 9.1.1, 9.0.6, and 8.2.12, an attacker can craft a special web request that can result in reflected cross-site scripting (XSS) on the “/app/search/table” web endpoint. Exploitation of this vulnerability can lead to the execution of arbitrary commands on the Splunk platform instance.

CVE-2023-40592
Unclassified
Aug 30, 2023
Medium6.5Splunk

Medium [CVE-2023-40594] In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.

CVE-2023-40594
Unclassified
Aug 30, 2023
Medium6.3Splunk

Medium [CVE-2023-40593] In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.

CVE-2023-40593
Unclassified
Aug 30, 2023
High7.1QNAP

High [CVE-2023-34971] QTS: inadequate encryption strength vulnerability has been reported to affect QNAP operating systems.

An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h4.5.4.2476 build 20230728 and later

CVE-2023-34971
Unclassified
Aug 24, 2023
Low3.1QNAP

Low [CVE-2023-34973] QTS: insufficient entropy vulnerability has been reported to affect QNAP operating systems.

An insufficient entropy vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to predict secret via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

CVE-2023-34973
Unclassified
Aug 24, 2023
Low3.5QNAP

Low [CVE-2023-34972] QTS: cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems.

A cleartext transmission of sensitive information vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to read the contents of unexpected sensitive data via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later

CVE-2023-34972
Unclassified
Aug 24, 2023
High7.8F5

High [CVE-2023-38418] The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38418
Unclassified
Aug 2, 2023
High7.5F5

High [CVE-2023-38138] reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which

A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38138
Unclassified
Aug 2, 2023
High7.1F5

High [CVE-2023-36858] insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may

An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-36858
Unclassified
Aug 2, 2023
Medium6.0F5

Medium [CVE-2023-3470] Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account

Specific F5 BIG-IP platforms with Cavium Nitrox FIPS HSM cards generate a deterministic password for the Crypto User account. The predictable nature of the password allows an authenticated user with TMSH access to the BIG-IP system, or anyone with physical access to the FIPS HSM, the information required to generate the correct password. On vCMP systems, all Guests share the same deterministic password, allowing those with TMSH access on one Guest to access keys of a different Guest. The following BIG-IP hardware platforms are affected: 10350v-F, i5820-DF, i7820-DF, i15820-DF, 5250v-F, 7200v-F, 10200v-F, 6900-F, 8900-F, 11000-F, and 11050-F. The BIG-IP rSeries r5920-DF and r10920-DF are not affected, nor does the issue affect software FIPS implementations or network HSM configurations. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-3470
Unclassified
Aug 2, 2023
Medium5.4F5

Medium [CVE-2023-38423] cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38423
Unclassified
Aug 2, 2023
Medium4.3F5

Medium [CVE-2023-38419] authenticated attacker with guest privileges or higher

An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-38419
Unclassified
Aug 2, 2023
Medium4.4F5

Medium [CVE-2023-36494] F5OS: Audit logs on F5OS-A may contain undisclosed sensitive information.

Audit logs on F5OS-A may contain undisclosed sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-36494
Unclassified
Aug 2, 2023
High8.6Splunk

High [CVE-2023-3997] Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal

Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.

CVE-2023-3997
Unclassified
Jul 31, 2023
High7.2Check Point

High [CVE-2023-28130] Gaia: Local user may lead to privilege escalation using Gaia Portal hostnames page.

Local user may lead to privilege escalation using Gaia Portal hostnames page.

CVE-2023-28130
Unclassified
Jul 26, 2023
High7.8Check Point

High [CVE-2023-28133] Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

CVE-2023-28133
Unclassified
Jul 23, 2023
Critical9.1MikroTik

Critical [CVE-2023-30799] RouterOS: MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue.

A new CVE has been published, which describes a policy elevation issue, where a logged in administrator with “policy” permissions (able to grant additional permissions to any user on the router), is also able to send crafted configuration commands, that are exchanged internally by the router software components and normally are rejected when sent by a user. This can be used as a stepping stone to execute arbitrary code on the router, allowing the connected user to gain control of the underlying operating system upon which RouterOS runs. To be able to use this discovered exploit, one would need administrative access to RouterOS, i.e. a known username and password, as well as a ways to connect (no firewall). This is not the only way how a logged in administrator user with such a high access level (as required for this exploit) can compromise the router. Other possibilities include: saving, modifying and restoring configuration backup; installing additional software packages; using another device on the local network to perform network reinstall of the router to a known vulnerable version. Affected product named by the advisory: MikroTik RouterOS.

CVE-2023-30799
RouterOS
Jul 19, 2023
High8.8Atlassian

High [CVE-2023-22506] Confluence: This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version…

This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker to modify the actions taken by a system call and execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to latest version. If you're unable to upgrade to latest, upgrade to one of these fixed versions: 9.2.3 and 9.3.1. See the release notes ([ ]). You can download the latest version of Bamboo Data Center and Bamboo Server from the download center ([ ]). This vulnerability was reported via our Penetration Testing program. Affected products named by the advisory: Confluence.

CVE-2023-22506
Unclassified
Jul 19, 2023
High8.8Atlassian

High [CVE-2023-22508] Confluence Data Center: This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of…

This High severity RCE (Remote Code Execution) vulnerability known as CVE-2023-22508 was introduced in version 6.1.0 of Confluence Data Center & Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and no user interaction. Atlassian recommends that you upgrade your instance to avoid this bug using the following options: * Upgrade to a Confluence feature release greater than or equal to 8.2.0 (ie: 8.2, 8.2, 8.4, etc...) * Upgrade to a Confluence 7.19 LTS bugfix release greater than or equal to 7.19.8 (ie: 7.19.8, 7.19.9, 7.19.10, 7.19.11, etc...) * Upgrade to a Confluence 7.13 LTS bugfix release greater than or equal to 7.13.20 (Release available early August) See the release notes ( ). You can download the latest version of Data Center & Server from the download center ( ). If you are unable to upgrade your instance please use the following guide to workaround the issue This vulnerability was discovered by a private user and reported via our Bug Bounty program.

CVE-2023-22508
Unclassified
Jul 18, 2023