Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2024-0012 +1] PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015)
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines. This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software on PA-Series, VM-Series, and CN-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access are not impacted by this vulnerability.
Critical [CVE-2024-45492] Libexpat Vulnerability in NetApp Products
Multiple NetApp products incorporate libexpat. libexpat versions prior to 2.6.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), SAN Host Utilities for Windows. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2024-9486] Proxmox: security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during…
A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine images built using the Proxmox provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their nodes use VM images created via the Image Builder project with its Proxmox provider.
Critical [CVE-2024-38124] Windows Netlogon Elevation of Privilege Vulnerability
Windows Netlogon Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.
Critical [CVE-2024-6593] WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected product named by the advisory: SSO Agent.
Critical [CVE-2024-6592] WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials. Affected products named by the advisory: SSO Client; SSO Agent.
Critical SQL Injection and Command Injection Advisory
SQL Injection and Command Injection Advisory
Critical [CVE-2024-30080] Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 10 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.
Critical [CVE-2024-32766] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Critical [CVE-2024-32764] myQNAPcloud: missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link.
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following version: myQNAPcloud Link 2.4.51 and later
Critical [CVE-2023-47222] exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on.
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later
Critical [CVE-2024-21899] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Critical [CVE-2024-21410] Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft Exchange Server 2016 Cumulative Update 23; Microsoft Exchange Server 2019 Cumulative Update 13; Microsoft Exchange Server 2019 Cumulative Update 14.
Critical [CVE-2023-45025] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QTS 4.5.4.2627 build 20231225 and later QuTS hero h4.5.4.2626 build 20231225 and later QuTScloud c5.1.5.2651 and later
Critical [CVE-2023-22527] template injection vulnerability on older versions of Confluence Data Center and Server
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.
Critical [CVE-2023-7028] Weak Password Recovery Mechanism for Forgotten Password in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Critical [CVE-2023-22524] Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability.
Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.
Critical [CVE-2023-29974] issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
Critical [CVE-2023-46604] Remote Code Execution Vulnerability in Apache ActiveMQ
Remote Code Execution Vulnerability in Apache ActiveMQ
Critical [CVE-2023-23369] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.2 ( 2023/05/04 ) and later QTS 5.1.0.2399 build 20230515 and later QTS 4.3.6.2441 build 20230621 and later Media Streaming add-on 500.1.1.2 ( 2023/06/12 ) and later