Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.3Check Point

High [CVE-2024-24910] local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows…

A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

CVE-2024-24910
Unclassified
Apr 18, 2024
High8.1Splunk

High [CVE-2024-29946] In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.

CVE-2024-29946
Splunk Enterprise
Mar 27, 2024
High7.2Splunk

High [CVE-2024-29945] In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the…

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either Splunk Enterprise runs in debug mode or the JsonWebToken component has been configured to log its activity at the DEBUG logging level.

CVE-2024-29945
Splunk Enterprise
Mar 27, 2024
High8.8Atlassian

High [CVE-2024-21677] Confluence Data Center: This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center.

This High severity Path Traversal vulnerability was introduced in version 6.13.0 of Confluence Data Center. This Path Traversal vulnerability, with a CVSS Score of 8.3, allows an unauthenticated attacker to exploit an undefinable vulnerability which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Data Center Atlassian recommends that Confluence Data Center customers upgrade to the latest version and that Confluence Server customers upgrade to the latest 8.5.x LTS version. This vulnerability was reported via our Bug Bounty program.

CVE-2024-21677
Confluence
Mar 19, 2024
High7.2Aruba

High [CVE-2024-25613] ArubaOS: Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2024-25613
AOS-8 MobilityWireless & ControllersArubaOS
Mar 5, 2024
High7.2Aruba

High [CVE-2024-26298] Vulnerabilities in the ClearPass Policy Manager web-based management interface

Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

CVE-2024-26298
ClearPassClearPass Policy Manager
Feb 27, 2024
High7.2Atlassian

High [CVE-2024-21682] Confluence: This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions).

This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an agent with Jira Service Management Cloud, Data Center or Server. It detects hardware and software that is connected to your local network and extracts detailed information about each asset. This data can then be imported into Assets in Jira Service Management to help you manage all of the devices and configuration items within your local network. This Injection vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Assets Discovery customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions See the release notes ( ). You can download the latest version of Assets Discovery from the Atlassian Marketplace ( ). This vulnerability was reported via our Penetration Testing program. Affected products named by the advisory: Confluence.

CVE-2024-21682
ConfluenceJira
Feb 20, 2024
High8.5Atlassian

High [CVE-2024-21678] Confluence Data Center: This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center.

This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser which has high impact to confidentiality, low impact to integrity, no impact to availability, and requires no user interaction. Atlassian recommends that Confluence Data Center customers upgrade to the latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions: ||Affected versions||Fixed versions|| |from 8.7.0 to 8.7.1|8.8.0 recommended or 8.7.2| Server See the release notes ([ ]). You can download the latest version of Confluence Data Center from the download center ([ ]). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence Server.

CVE-2024-21678
Confluence
Feb 20, 2024
High7.5F5

High [CVE-2024-24990] When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-24990
NGINX
Feb 14, 2024
High7.5F5

High [CVE-2024-24775] When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-24775
Unclassified
Feb 14, 2024
High7.5F5

High [CVE-2024-23982] When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the table in the F5 Security Advisory for a complete list of affected classification signature files. NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23982
BIG-IP
Feb 14, 2024
High7.5F5

High [CVE-2024-23979] When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured…

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23979
Unclassified
Feb 14, 2024
High7.5F5

High [CVE-2024-23805] BIG-IP: Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB variables avr. IncludeServerInURI or avr. CollectOnlyHostnameFromURI are enabled. For BIG-IP Advanced WAF and ASM, this may occur when either a DoS or Bot Defense profile is configured on a virtual server and the DB variables avr. For more information about the HTTP Analytics profile and the Collect URLs setting, refer to K30875743: Create a new Analytics profile and attach it to your virtual servers. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23805
BIG-IP
Feb 14, 2024
High7.5F5

High [CVE-2024-23314] When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23314
BIG-IPBIG-IP Next
Feb 14, 2024
High7.5F5

High [CVE-2024-23308] When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed…

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content Profile for an Allowed URL with "Apply value and content signatures and detect threat campaigns." Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23308
BIG-IP
Feb 14, 2024
High7.1F5

High [CVE-2024-23306] BIG-IP Next: vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-23306
BIG-IPBIG-IP Next
Feb 14, 2024
High7.2F5

High [CVE-2024-22389] When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the…

When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-22389
BIG-IP
Feb 14, 2024
High8.7F5

High [CVE-2024-22093] When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST…

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-22093
Unclassified
Feb 14, 2024
High7.5F5

High [CVE-2024-21849] When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic

When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-21849
BIG-IP
Feb 14, 2024
High7.5F5

High [CVE-2024-21789] When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-21789
BIG-IP
Feb 14, 2024