Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Splunk

High [CVE-2024-23678] In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data

In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data. This results in the unsafe deserialization of untrusted data from a separate disk partition on the machine. This vulnerability only affects Splunk Enterprise for Windows.

CVE-2024-23678
Splunk Enterprise
Jan 22, 2024
High7.4QNAP

High [CVE-2023-47560] QuMagie: OS command injection vulnerability has been reported to affect QuMagie.

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVE-2023-47560
Applications
Jan 5, 2024
High8.8QNAP

High [CVE-2023-41288] Video Station: OS command injection vulnerability has been reported to affect Video Station.

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later

CVE-2023-41288
Applications
Jan 5, 2024
High7.5QNAP

High [CVE-2023-39296] QTS: prototype pollution vulnerability has been reported to affect several QNAP operating system versions.

A prototype pollution vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to override existing attributes with ones that have incompatible type, which may lead to a crash via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later Affected products named by the advisory: QuTS hero.

CVE-2023-39296
QTSQuTS hero
Jan 5, 2024
High8.0QNAP Exploited CISA KEV

High [CVE-2023-47565] QVR: OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x.

An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QVR Firmware 5.0.0 and later

CVE-2023-47565
Surveillance (QVR)
Dec 8, 2023
High8.8pfSense

High [CVE-2023-48123] issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

CVE-2023-48123
pfSense PluspfSense CE
Dec 6, 2023
High8.8Atlassian

High [CVE-2023-22523] This vulnerability, if exploited

This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets Discovery agent.

CVE-2023-22523
Unclassified
Dec 6, 2023
High8.8Atlassian

High [CVE-2023-22522] Confluence Data Center: This Template Injection vulnerability

This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly accessible Confluence Data Center and Server versions as listed below are at risk and require immediate attention. See the advisory for additional details Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.

CVE-2023-22522
Confluence
Dec 6, 2023
High8.0Splunk

High [CVE-2023-46214] In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language…

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

CVE-2023-46214
Splunk Enterprise
Nov 16, 2023
High8.8pfSense

High [CVE-2023-42326] issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

CVE-2023-42326
Unclassified
Nov 14, 2023
High7.8Check Point

High [CVE-2023-28134] Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security

Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CVE-2023-28134
Harmony (Endpoint/Mobile)
Nov 12, 2023
High7.4QNAP

High [CVE-2023-41285] QuMagie: SQL injection vulnerability has been reported to affect QuMagie.

A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later

CVE-2023-41285
Applications
Nov 10, 2023
High8.8QNAP

High [CVE-2023-39295] QuMagie: OS command injection vulnerability has been reported to affect QuMagie.

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QuMagie 2.1.3 and later

CVE-2023-39295
Applications
Nov 10, 2023
High7.2pfSense

High [CVE-2023-29975] issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

CVE-2023-29975
pfSense CE
Nov 9, 2023
High7.5QNAP

High [CVE-2023-39299] Music Station: path traversal vulnerability has been reported to affect Music Station.

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later

CVE-2023-39299
Applications
Nov 3, 2023
High8.8F5 Exploited CISA KEV

High [CVE-2023-46748] authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may

An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-46748
BIG-IP
Oct 26, 2023
High8.8QNAP

High [CVE-2023-23373] OS command injection vulnerability has been reported to affect QUSBCam2.

An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following version: QUSBCam2 2.0.3 ( 2023/06/15 ) and later

CVE-2023-23373
Unclassified
Oct 20, 2023
High7.1Sophos

High [CVE-2023-5552] Sophos Firewall: password disclosure vulnerability in the Secure PDF eXchange (SPX) feature

A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.

CVE-2023-5552
Sophos Firewall (XGS/SFOS)
Oct 18, 2023
High7.5QNAP

High [CVE-2023-32974] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTScloud c5.1.0.2498 and later

CVE-2023-32974
QTSQuTS hero
Oct 13, 2023
High7.3F5

High [CVE-2023-5450] insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may

An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-5450
BIG-IP
Oct 10, 2023