Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

5326 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.3Sophos

Low [CVE-2022-0652] Sophos UTM: Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions.

Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

CVE-2022-0652
Unclassified
Mar 22, 2022
Critical9.8Atlassian

Critical [CVE-2021-43958] Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login…

Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing user credentials for authentication via a improper restriction of excess authentication attempts vulnerability.

CVE-2021-43958
Unclassified
Mar 16, 2022
High7.5Atlassian

High [CVE-2020-29446 +1] Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files

Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IDOR) vulnerability in the WEB-INF directory and bypass the fix for CVE-2020-29446 due to a lack of url decoding. The affected versions are before version 4.8.9.

CVE-2020-29446CVE-2021-43957
Unclassified
Mar 16, 2022
Medium6.1Atlassian

Medium [CVE-2021-43956] The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML…

The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitrary HTML and/or JavaScript via a prototype pollution vulnerability.

CVE-2021-43956
Unclassified
Mar 16, 2022
Medium4.3Atlassian

Medium [CVE-2021-43955] The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers…

The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote attackers to obtain information about installation directories via information disclosure vulnerability.

CVE-2021-43955
Unclassified
Mar 16, 2022
Medium4.3Atlassian

Medium [CVE-2021-43954] The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add…

The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have 'can add repository permission', to enumerate the existence of internal network and filesystem resources via a Server-Side Request Forgery (SSRF) vulnerability.

CVE-2021-43954
Unclassified
Mar 14, 2022
Medium6.5pfSense

Medium [CVE-2022-21132] Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and…

Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.

CVE-2022-21132
Unclassified
Mar 10, 2022
High7.2Atlassian

High [CVE-2021-43944] This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been…

This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system administrator permissions to execute arbitrary code via Template Injection leading to Remote Code Execution (RCE) in the Email Templates feature. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43944
Unclassified
Mar 8, 2022
Medium6.1Sophos

Medium [CVE-2021-36809] local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially…

A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.

CVE-2021-36809
Unclassified
Mar 8, 2022
High8.8pfSense

High [CVE-2021-41282] pfSense: diag_routes.php in pfSense 2.5.2 allows sed data injection.

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2021-41282
Unclassified
Mar 1, 2022
Medium4.8Atlassian

Medium [CVE-2021-43945] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3.

CVE-2021-43945
Unclassified
Feb 28, 2022
Medium5.3QNAP

Medium [CVE-2021-34361] QTS: cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVE-2021-34361
Unclassified
Feb 25, 2022
Medium4.8Atlassian

Medium [CVE-2021-43943] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privileges to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the "Object Schema" field of /secure/admin/InsightDefaultCustomFieldConfig.jspa. The affected versions are before version 4.21.0.

CVE-2021-43943
Unclassified
Feb 24, 2022
High7.8Atlassian

High [CVE-2021-43940] Affected versions of Atlassian Confluence Server and Data Center

Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence Server and Data Center on Windows. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2021-43940
Unclassified
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43948] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view the names of private objects via an Improper Authorization vulnerability in the "Move objects" feature. The affected versions are before version 4.21.0.

CVE-2021-43948
Unclassified
Feb 15, 2022
Medium6.5Atlassian

Medium [CVE-2021-43941] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including CsvFieldMappingsPage.jspa and ImporterValueMappingsPage.jspa) via a Cross-Site Request Forgery (CSRF) vulnerability in the jira-importers-plugin. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3.

CVE-2021-43941
Unclassified
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43953] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5.

CVE-2021-43953
Unclassified
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43950] Affected versions of Atlassian Jira Service Management Server and Data Center

Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view import source configuration information via a Broken Access Control vulnerability in the Insight Import Source feature. The affected versions are before version 4.21.0.

CVE-2021-43950
Unclassified
Feb 15, 2022
Medium4.3Atlassian

Medium [CVE-2021-43952] Affected versions of Atlassian Jira Server and Data Center

Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default configuration of fields via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/RestoreDefaults.jspa endpoint. The affected versions are before version 8.21.0.

CVE-2021-43952
Unclassified
Feb 15, 2022
Medium6.5QNAP

Medium [CVE-2021-38679] QNAP NAS: improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server.

An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.22 and later

CVE-2021-38679
Unclassified
Feb 11, 2022