Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

569 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8MS Server

Critical [CVE-2023-21692] Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2023-21692
Windows Server
Feb 14, 2023
Critical9.8MS Server

Critical [CVE-2023-21690] Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2012; Windows Server 2012 (Server Core installation); and 7 more. Affected products named by the advisory: Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); Windows Server 2022.

CVE-2023-21690
Windows Server
Feb 14, 2023
Critical9.8MS Server

Critical [CVE-2023-21803] Windows iSCSI Discovery Service Remote Code Execution Vulnerability

Windows iSCSI Discovery Service Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation).

CVE-2023-21803
Windows Server
Feb 14, 2023
Critical9.1Atlassian

Critical [CVE-2023-22501] authentication vulnerability was discovered in Jira Service Management Server and Data Center which

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: - If the attacker is included on Jira issues or requests with these users, or - If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.

CVE-2023-22501
Jira
Feb 1, 2023
Critical9.8QNAP

Critical [CVE-2022-27596] QTS: vulnerability has been reported to affect QNAP device running QuTS hero, QTS.

A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 20221201 and later

CVE-2022-27596
QTSQuTS hero
Jan 30, 2023
Critical9.0Proxmox

Critical [CVE-2022-31358] reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

CVE-2022-31358
Virtual Environment (VE)
Dec 14, 2022
Critical9.8Proxmox

Critical [CVE-2022-35508] Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

CVE-2022-35508
Virtual Environment (VE)Mail Gateway (PMG)
Dec 4, 2022
Critical9.8Atlassian

Critical [CVE-2022-43782] Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application

Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3

CVE-2022-43782
Bamboo / Crowd / Fisheye
Nov 17, 2022
Critical9.8Atlassian

Critical [CVE-2022-43781] Bitbucket: There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center.

There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.

CVE-2022-43781
Bitbucket
Nov 17, 2022
Critical9.8Sophos

Critical [CVE-2022-3980] Sophos Mobile: XML External Entity (XEE) vulnerability

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

CVE-2022-3980
Sophos Mobile / Connect
Nov 16, 2022
Critical9.8NetApp

Critical [CVE-2022-40674] libexpat Vulnerability in NetApp Products

Multiple NetApp products incorporate libexpat. libexpat versions prior to 2.4.9 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP 9, ONTAP Select Deploy administration utility, OnCommand Workflow Automation, SAN Host Utilities for Windows. NetApp states there is no workaround available at this time.

CVE-2022-40674
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Oct 28, 2022
Critical9.6Fortinet Exploited CISA KEV

Critical [CVE-2022-40684] Fortinet FortiOS, FortiProxy, FortiSwitchManager: authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests. Affected product named by the advisory: Fortinet FortiOS, FortiProxy, FortiSwitchManager.

CVE-2022-40684
FortiGateFirewallFortiOSFortiProxy
Oct 18, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-3236] Sophos Firewall: code injection vulnerability in the User Portal and Webadmin

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-3236
Sophos Firewall (XGS/SFOS)
Sep 23, 2022
Critical10.0QNAP Exploited CISA KEV

Critical [CVE-2022-27593] QTS: externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-27593
QTSApplications
Sep 8, 2022
Critical9.8pfSense

Critical [CVE-2022-31814] pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

CVE-2022-31814
Unclassified
Sep 5, 2022
Critical9.8Check Point

Critical [CVE-2022-23747] In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur

In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback.

CVE-2022-23747
Unclassified
Aug 17, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26138] The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the…

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-26138
Confluence
Jul 20, 2022
Critical9.8Atlassian

Critical [CVE-2022-26136] Confluence: vulnerability in multiple Atlassian products

A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Affected products named by the advisory: Confluence; Jira Service Management; Bitbucket; Crowd; and 2 more.

CVE-2022-26136
ConfluenceJiraBitbucketBamboo / Crowd / Fisheye
Jul 20, 2022
Critical9.0Splunk

Critical [CVE-2022-32158] Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

CVE-2022-32158
Splunk EnterpriseUniversal Forwarder
Jun 15, 2022
Critical9.8Atlassian Exploited CISA KEV

Critical [CVE-2022-26134] In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-26134
Confluence
Jun 3, 2022