Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.5F5

High [CVE-2023-22374] BIG-IP: format string vulnerability exists in iControl SOAP

A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-22374
BIG-IP
Feb 1, 2023
High8.7F5

High [CVE-2022-41800] In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role

In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-41800
BIG-IP
Dec 7, 2022
High8.8F5

High [CVE-2022-41622] BIG-IP: In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.

In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-41622
BIG-IPBIG-IQ
Dec 7, 2022
High8.8Sophos

High [CVE-2022-3713] Sophos Firewall: code injection vulnerability

A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3713
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
High7.2Sophos

High [CVE-2022-3696] Sophos Firewall: post-auth code injection vulnerability

A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3696
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
High7.2Sophos

High [CVE-2022-3226] Sophos Firewall: OS command injection vulnerability allows admins to execute code

An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3226
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
High7.5Check Point

High [CVE-2022-23746] The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX).

The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

CVE-2022-23746
Unclassified
Nov 30, 2022
High7.8Check Point Exploited CISA KEV

High [CVE-2022-23748] mDNSResponder.exe is vulnerable to DLL Sideloading attack.

mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

CVE-2022-23748
Unclassified
Nov 17, 2022
High8.1MS Server

High [CVE-2022-37966] Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability

Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2008 Service Pack 2; Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2 (Server Core installation); and 9 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 1 more.

CVE-2022-37966
Windows Server
Nov 9, 2022
High7.5Splunk

High [CVE-2022-43572] In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or…

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.

CVE-2022-43572
Splunk Enterprise
Nov 4, 2022
High8.8Splunk

High [CVE-2022-43570] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.

CVE-2022-43570
Splunk Enterprise
Nov 4, 2022
High8.0Splunk

High [CVE-2022-43569] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scripts that can lead to persistent cross-site scripting (XSS) in the object name of a Data Model.

CVE-2022-43569
Splunk Enterprise
Nov 4, 2022
High8.8Splunk

High [CVE-2022-43568] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via JavaScript Object Notation (JSON) in a query parameter when output_mode=radio.

CVE-2022-43568
Splunk Enterprise
Nov 4, 2022
High8.8Splunk

High [CVE-2022-43567] In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.

CVE-2022-43567
Splunk Enterprise
Nov 4, 2022
High7.3Splunk

High [CVE-2022-43566] In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run risky commands using a more privileged user’s permissions to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

CVE-2022-43566
Splunk Enterprise
Nov 4, 2022
High8.1Splunk

High [CVE-2022-43565] In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON)

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notation (JSON) lets an attacker bypass SPL safeguards for risky commands. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser.

CVE-2022-43565
Splunk Enterprise
Nov 4, 2022
High8.1Splunk

High [CVE-2022-43563] In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

CVE-2022-43563
Splunk Enterprise
Nov 4, 2022
High8.8Splunk

High [CVE-2022-43571] In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.

CVE-2022-43571
Splunk Enterprise
Nov 3, 2022
High7.5F5

High [CVE-2022-41836] When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests

When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

CVE-2022-41836
Unclassified
Oct 19, 2022
High7.5F5

High [CVE-2022-41833] In all BIG-IP 13.1.x versions

In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate.

CVE-2022-41833
BIG-IP
Oct 19, 2022