Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5F5

High [CVE-2024-39792] When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-39792
NGINX
Aug 14, 2024
High7.5F5

High [CVE-2024-39778] When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests

When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-39778
BIG-IP
Aug 14, 2024
High7.2Aruba

High [CVE-2024-41915] vulnerability in the web-based management interface of ClearPass Policy Manager could

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.

CVE-2024-41915
ClearPassClearPass Policy Manager
Jul 30, 2024
High7.2Aruba

High [CVE-2024-41135] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

CVE-2024-41135
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-33519] vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-33519
EdgeConnect SD-WAN
Jul 24, 2024
High8.1Aruba

High [CVE-2024-41914] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2024-41914
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-22443] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-22443
EdgeConnect SD-WAN
Jul 24, 2024
High8.1Atlassian

High [CVE-2024-21687] Confluence: This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of…

This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This File Inclusion vulnerability, with a CVSS Score of 8.1, allows an authenticated attacker to get the application to display the contents of a local file, or execute a different files already stored locally on the server which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires no user interaction. Atlassian recommends that Bamboo Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes ( ). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence.

CVE-2024-21687
ConfluenceBamboo / Crowd / Fisheye
Jul 16, 2024
High8.7Atlassian

High [CVE-2024-21686] Confluence Data Center: This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server.

This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score of 7.3, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, high impact to integrity, no impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions listed on this CVE See the release notes ( ). This vulnerability was reported via our Bug Bounty program.

CVE-2024-21686
Confluence
Jul 16, 2024
High8.1Splunk

High [CVE-2024-36997] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a persistent cross-site scripting (XSS) exploit.

CVE-2024-36997
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
High7.5Splunk

High [CVE-2024-36991] In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

CVE-2024-36991
Splunk Enterprise
Jul 1, 2024
High7.1Splunk

High [CVE-2024-36989] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin or power Splunk roles could create notifications in Splunk Web Bulletin Messages that all users on the instance receive.

CVE-2024-36989
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
High8.8Splunk

High [CVE-2024-36985] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the “splunk_archiver“ application.

CVE-2024-36985
Splunk Enterprise
Jul 1, 2024
High8.8Splunk

High [CVE-2024-36984] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

CVE-2024-36984
Splunk Enterprise
Jul 1, 2024
High8.0Splunk

High [CVE-2024-36983] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.

CVE-2024-36983
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
High7.5Splunk

High [CVE-2024-36982] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.

CVE-2024-36982
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
High8.6Check Point Exploited CISA KEV

High [CVE-2024-24919] Information disclosure

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. Affected product named by the advisory: Check Point Quantum Gateway, Spark Gateway and CloudGuard Network.

CVE-2024-24919
Quantum Gateway / GaiaCloudGuard
May 28, 2024
High8.8Atlassian

High [CVE-2024-21683] This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the release notes You can download the latest version of Confluence Data Center and Server from the download center. This vulnerability was found internally.

CVE-2024-21683
Confluence
May 21, 2024
High7.2QNAP

High [CVE-2024-27130] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-27130
QTSQuTS hero
May 21, 2024
High7.2QNAP

High [CVE-2024-27127] QTS: double free vulnerability has been reported to affect several QNAP operating system versions.

A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute arbitrary code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-27127
QTSQuTS hero
May 21, 2024