Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5345 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.2Atlassian

High [CVE-2022-36799] This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been…

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. In this case the security improvement was to protect against using the XStream library to be able to execute arbitrary code in velocity templates. The affected versions are before version 8.13.19, from version 8.14.0 before 8.20.7, and from version 8.21.0 before 8.22.1.

CVE-2022-36799
Unclassified
Aug 1, 2022
Medium5.7Atlassian

Medium [CVE-2021-43959] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability in the CSV importing feature of JSM Insight. When running in an environment like Amazon EC2, this flaw may be used to access to a metadata resource that provides access credentials and other potentially confidential information. The affected versions are before version 4.13.20, from version 4.14.0 before 4.20.8, and from version 4.21.0 before 4.22.2.

CVE-2021-43959
Unclassified
Jul 26, 2022
Medium5.4Atlassian

Medium [CVE-2020-36290] The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from…

The Livesearch macro in Confluence Server and Data Center before version 7.4.5, from version 7.5.0 before 7.6.3, and from version 7.7.0 before version 7.7.4 allows remote attackers with permission to edit a page or blog to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the page excerpt functionality.

CVE-2020-36290
Unclassified
Jul 26, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26138] The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the…

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-26138
Unclassified
Jul 20, 2022
Critical9.8Atlassian

Critical [CVE-2022-26136] Confluence: vulnerability in multiple Atlassian products

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Affected products named by the advisory: Confluence; Jira Service Management; Bitbucket; Crowd; and 2 more.

CVE-2022-26136
Unclassified
Jul 20, 2022
High8.8Atlassian

High [CVE-2022-26137] Confluence: vulnerability in multiple Atlassian products

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Affected products named by the advisory: Confluence; Jira Service Management; Bitbucket; Crowd; and 2 more.

CVE-2022-26137
Unclassified
Jul 20, 2022
High7.5Check Point

High [CVE-2022-23745] potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).

A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information.

CVE-2022-23745
Unclassified
Jul 18, 2022
Low2.3Check Point

Low [CVE-2022-23744] Check Point Endpoint before version E86.50 failed to protect against specific registry change

Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.

CVE-2022-23744
Unclassified
Jul 7, 2022
Medium6.5Atlassian

Medium [CVE-2022-26135] vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined

A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user who joined via the sign-up feature) to perform a full read server-side request forgery via a batch endpoint. This affects Atlassian Jira Server and Data Center from version 8.0.0 before version 8.13.22, from version 8.14.0 before 8.20.10, from version 8.21.0 before 8.22.4.

CVE-2022-26135
Unclassified
Jun 30, 2022
Critical9.0Splunk

Critical [CVE-2022-32158] Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

CVE-2022-32158
Unclassified
Jun 15, 2022
High7.5Splunk

High [CVE-2022-32157] Splunk Enterprise: Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles.

Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients ( ). Once enabled, deployment servers can manage only Universal Forwarder versions 9.0 and higher. Though the vulnerability does not directly affect Universal Forwarders, remediation requires updating all Universal Forwarders that the deployment server manages to version 9.0 or higher prior to enabling the remediation.

CVE-2022-32157
Unclassified
Jun 15, 2022
High8.1Splunk

High [CVE-2022-32156] In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS…

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation for the Splunk CLI to enable the remediation. The vulnerability does not affect the Splunk Cloud Platform. At the time of publishing, we have no evidence of exploitation of this vulnerability by external parties. The issue requires conditions beyond the control of a potential bad actor such as a machine-in-the-middle attack. Hence, Splunk rates the complexity of the attack as High.

CVE-2022-32156
Unclassified
Jun 15, 2022
High7.5Splunk

High [CVE-2022-32155] Universal Forwarder: In universal forwarder versions before 9.0, management services are available remotely by default.

In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If management services are not required in versions before 9.0, set disableDefaultPort = true in server.conf OR allowRemoteLogin = never in server.conf OR mgmtHostPort = localhost in web.conf. See Configure universal forwarder management security ( ) for more information on disabling the remote management services.

CVE-2022-32155
Unclassified
Jun 15, 2022
High8.1Splunk

High [CVE-2022-32153] Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not…

Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates were not vulnerable. However, an attacker with administrator credentials could add a peer without a valid certificate and connections from misconfigured nodes without valid certificates did not fail by default. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications ( ) to enable the remediation.

CVE-2022-32153
Unclassified
Jun 15, 2022
High7.4Splunk

High [CVE-2022-32151] The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the…

The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python 3 client libraries now verify server certificates by default and use the appropriate CA certificate stores for each library. Apps and add-ons that include their own HTTP libraries are not affected. For Splunk Enterprise, update to Splunk Enterprise version 9.0 and Configure TLS host name validation for Splunk-to-Splunk communications ( ) to enable the remediation.

CVE-2022-32151
Unclassified
Jun 15, 2022
Medium6.8Splunk

Medium [CVE-2022-32154] Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token

Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to some custom and potentially risky commands ( ) for more information. Note that the attack is browser-based and an attacker cannot exploit it at will.

CVE-2022-32154
Unclassified
Jun 15, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26134] In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-26134
Unclassified
Jun 3, 2022
Medium5.3QNAP

Medium [CVE-2021-34360] QTS: cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server.

A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVE-2021-34360
Unclassified
May 26, 2022
High7.8Check Point

High [CVE-2020-0896 +1] Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory…

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.

CVE-2020-0896CVE-2022-23742
Unclassified
May 12, 2022
High7.8Check Point

High [CVE-2022-23743] Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process

Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary file write, leading to execution of code as local system, in ZoneAlarm versions before v15.8.211.192119

CVE-2022-23743
Unclassified
May 11, 2022