Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5345 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5F5

Medium [CVE-2022-41770] In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all…

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource utilization, via undisclosed requests.

CVE-2022-41770
Unclassified
Oct 19, 2022
Medium4.9F5

Medium [CVE-2022-41694] In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ…

In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate.

CVE-2022-41694
Unclassified
Oct 19, 2022
Medium5.3F5

Medium [CVE-2022-36795] In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections.

CVE-2022-36795
Unclassified
Oct 19, 2022
Low3.7F5

Low [CVE-2022-41983] On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all…

On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied.

CVE-2022-41983
Unclassified
Oct 19, 2022
LowCommvault

Low [CVE-2022-42889] Remote Code Execution Vulnerability in Apache Common Text

Remote Code Execution Vulnerability in Apache Common Text

CVE-2022-42889
Unclassified
Oct 18, 2022
High8.8Atlassian

High [CVE-2022-36803] The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2

The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.

CVE-2022-36803
Unclassified
Oct 14, 2022
Medium4.9Atlassian

Medium [CVE-2022-36802] The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2

The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this issue to access internal network resources via a Server-Side Request Forgery. This can be exploited by a remote, unauthenticated attacker with Super Admin privileges by sending a specially crafted HTTP request.

CVE-2022-36802
Unclassified
Oct 14, 2022
Medium6.1pfSense

Medium [CVE-2022-42247] pfSense: pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.

pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

CVE-2022-42247
Unclassified
Oct 3, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-3236] Sophos Firewall: code injection vulnerability in the User Portal and Webadmin

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-3236
Unclassified
Sep 23, 2022
Critical10.0QNAP Exploited CISA KEV

Critical [CVE-2022-27593] QTS: externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-27593
Unclassified
Sep 8, 2022
High7.2Sophos

High [CVE-2022-1807] Sophos Firewall: Multiple SQLi vulnerabilities in Webadmin

Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.

CVE-2022-1807
Unclassified
Sep 7, 2022
Critical9.8pfSense

Critical [CVE-2022-31814] pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

CVE-2022-31814
Unclassified
Sep 5, 2022
High8.8Atlassian Exploited CISA KEV

High [CVE-2022-36804] Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before…

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVE-2022-36804
Unclassified
Aug 25, 2022
Critical9.8Check Point

Critical [CVE-2022-23747] In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

CVE-2022-23747
Unclassified
Aug 17, 2022
High7.4Splunk

High [CVE-2022-37437] Splunk Enterprise: When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS…

When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through Splunk Web and only applies to environments that have configured TLS certificate validation. It does not apply to Destinations configured directly in the outputs.conf configuration file. The vulnerability affects Splunk Enterprise version 9.0.0 and does not affect versions below 9.0.0, including the 8.1.x and 8.2.x versions.

CVE-2022-37437
Unclassified
Aug 16, 2022
Medium5.5Splunk

Medium [CVE-2022-37439] In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the…

In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.

CVE-2022-37439
Unclassified
Aug 16, 2022
Low2.6Splunk

Low [CVE-2022-37438] In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard

In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially leak information (for example, username, email, and real name) about Splunk users, when visited by another user through the drilldown component. The vulnerability requires user access to create and share dashboards using Splunk Web.

CVE-2022-37438
Unclassified
Aug 16, 2022
Medium6.1Atlassian

Medium [CVE-2022-36801] Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript

Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Reflected Cross-Site Scripting (RXSS) vulnerability in the TeamManagement.jspa endpoint. The affected versions are before version 8.20.8.

CVE-2022-36801
Unclassified
Aug 10, 2022
High7.2F5

High [CVE-2022-35735] In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an…

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuration utility in an undisclosed manner leading to a privilege escalation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-35735
Unclassified
Aug 4, 2022
High8.1F5

High [CVE-2022-35728] In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all…

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ version 8.x before 8.2.0 and all versions of 7.x, an authenticated user's iControl REST token may remain valid for a limited time after logging out from the Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-35728
Unclassified
Aug 4, 2022