Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5QNAP

High [CVE-2023-32974] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.0.2444 build 20230629 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTScloud c5.1.0.2498 and later

CVE-2023-32974
QTSQuTS hero
Oct 13, 2023
High7.3F5

High [CVE-2023-5450] insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may

An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-5450
BIG-IP
Oct 10, 2023
High7.4F5

High [CVE-2023-45226] The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials

The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers contains hardcoded credentials that may allow an attacker with the ability to intercept traffic to impersonate the SPK Secure Shell (SSH) server on those containers. This is only exposed when ssh debug is enabled. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-45226
BIG-IP
Oct 10, 2023
High8.7F5

High [CVE-2023-43746] BIG-IP: When running in Appliance mode, an authenticated user assigned the Administrator role

When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-43746
BIG-IP
Oct 10, 2023
High7.8F5

High [CVE-2023-38418 +1] The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process

The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerability is due to an incomplete fix for CVE-2023-38418. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-38418CVE-2023-43611
BIG-IP
Oct 10, 2023
High7.2F5

High [CVE-2023-42768] BIG-IP: When a non-admin user has been assigned an administrator role

When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST. BIG-IP non-admin user can still have access to iControl REST admin resource. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-42768
BIG-IP
Oct 10, 2023
High7.5F5

High [CVE-2023-41085] When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate.

When IPSec is configured on a Virtual Server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41085
Unclassified
Oct 10, 2023
High7.5F5

High [CVE-2023-40542] When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests

When TCP Verified Accept is enabled on a TCP profile that is configured on a Virtual Server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-40542
Unclassified
Oct 10, 2023
High8.1F5

High [CVE-2023-40537] BIG-IP: authenticated user's session cookie

An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility on a multi-blade VIPRION platform. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-40537
BIG-IP
Oct 10, 2023
High7.5F5

High [CVE-2023-40534] When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the…

When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-40534
Unclassified
Oct 10, 2023
High7.7QNAP

High [CVE-2023-23366] Music Station: path traversal vulnerability has been reported to affect Music Station.

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Music Station 5.3.22 and later

CVE-2023-23366
Applications
Oct 6, 2023
High8.1QNAP

High [CVE-2023-23364] Multimedia Console: buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems.

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: Multimedia Console 2.1.1 ( 2023/03/29 ) and later

CVE-2023-23364
Applications
Sep 22, 2023
High8.1QNAP

High [CVE-2023-23363] QTS: buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system.

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2441 build 20230621 and later

CVE-2023-23363
QTS
Sep 22, 2023
High8.8QNAP

High [CVE-2023-23362] QTS: OS command injection vulnerability has been reported to affect QNAP operating systems.

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QTS 4.5.4.2374 build 20230416 and later QuTS hero h4.5.4.2374 build 20230417 and later Affected products named by the advisory: QuTScloud.

CVE-2023-23362
QTSQuTS hero
Sep 22, 2023
High8.8Atlassian

High [CVE-2023-22513] Confluence: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Bitbucket Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bitbucket Data Center and Server 8.9: Upgrade to a release greater than or equal to 8.9.5 Bitbucket Data Center and Server 8.10: Upgrade to a release greater than or equal to 8.10.5 Bitbucket Data Center and Server 8.11: Upgrade to a release greater than or equal to 8.11.4 Bitbucket Data Center and Server 8.12: Upgrade to a release greater than or equal to 8.12.2 Bitbucket Data Center and Server 8.13: Upgrade to a release greater than or equal to 8.13.1 Bitbucket Data Center and Server 8.14: Upgrade to a release greater than or equal to 8.14.0 Bitbucket Data Center and Server version >= 8.0 and < 8.9: Upgrade to any of the listed fix versions. See the release notes ( ). This vulnerability was discovered by a private user and reported via our Bug Bounty program

CVE-2023-22513
ConfluenceBitbucket
Sep 19, 2023
High8.6Splunk

High [CVE-2023-4571] In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor

In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal application reads them, can run malicious code in the vulnerable application. This attack requires a user to use a terminal application that translates ANSI escape codes to read the malicious log file locally in the vulnerable terminal. The vulnerability also requires additional user interaction to succeed. The vulnerability does not directly affect Splunk ITSI. The indirect impact on Splunk ITSI can vary significantly depending on the permissions in the vulnerable terminal application, as well as where and how the user reads the malicious log file. For example, users can copy the malicious file from Splunk ITSI and read it on their local machine.

CVE-2023-4571
ES / ITSI / SOAR
Aug 30, 2023
High8.5Splunk

High [CVE-2023-40598] In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker

In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.

CVE-2023-40598
Splunk Enterprise
Aug 30, 2023
High7.8Splunk

High [CVE-2023-40597] In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.

CVE-2023-40597
Splunk Enterprise
Aug 30, 2023
High7.0Splunk

High [CVE-2023-40596] In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk…

In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.

CVE-2023-40596
Splunk Enterprise
Aug 30, 2023
High8.8Splunk

High [CVE-2023-40595] In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can execute a specially crafted query that they can then use to serialize untrusted data. The attacker can use the query to execute arbitrary code.

CVE-2023-40595
Splunk Enterprise
Aug 30, 2023