Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.2Sophos

High [CVE-2022-1807] Sophos Firewall: Multiple SQLi vulnerabilities in Webadmin

Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.

CVE-2022-1807
Sophos Firewall (XGS/SFOS)
Sep 7, 2022
High7.4Splunk

High [CVE-2022-37437] Splunk Enterprise: When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS…

When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and an Ingest Actions Destination through Splunk Web and only applies to environments that have configured TLS certificate validation. It does not apply to Destinations configured directly in the outputs.conf configuration file. The vulnerability affects Splunk Enterprise version 9.0.0 and does not affect versions below 9.0.0, including the 8.1.x and 8.2.x versions.

CVE-2022-37437
Splunk Enterprise
Aug 16, 2022
High7.5Check Point

High [CVE-2022-23745] potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).

A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information.

CVE-2022-23745
Unclassified
Jul 18, 2022
High7.8Check Point

High [CVE-2020-0896 +1] Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory…

Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links.

CVE-2020-0896CVE-2022-23742
Unclassified
May 12, 2022
High8.4Sophos

High [CVE-2021-25268] Sophos Firewall: Multiple XSS vulnerabilities in Webadmin

Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.

CVE-2021-25268
Sophos Firewall (XGS/SFOS)
May 5, 2022
High7.1QNAP

High [CVE-2021-44057] Photo Station: improper authentication vulnerability has been reported to affect QNAP device running Photo Station.

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 ( 2022/02/11 ) and later Photo Station 5.4.13 ( 2022/02/11 ) and later

CVE-2021-44057
Applications
May 5, 2022
High7.1QNAP

High [CVE-2021-44056] Video Station: improper authentication vulnerability has been reported to affect QNAP device running Video Station.

An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 and later Video Station 5.3.13 and later Video Station 5.1.8 and later

CVE-2021-44056
Applications
May 5, 2022
High8.8QNAP

High [CVE-2021-44051] QTS: command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS.

A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 5.0.0.1986 build 20220324 and later

CVE-2021-44051
QTSQuTS hero
May 5, 2022
High7.5Proxmox

High [CVE-2022-28142] Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM

Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.

CVE-2022-28142
Unclassified
Mar 29, 2022
High8.8pfSense

High [CVE-2021-41282] pfSense: diag_routes.php in pfSense 2.5.2 allows sed data injection.

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2021-41282
Unclassified
Mar 1, 2022
High8.8Sophos

High [CVE-2022-0366] authenticated and authorized agent user could potentially gain administrative access

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

CVE-2022-0366
Unclassified
Feb 2, 2022
HighCommvault Exploited CISA KEV

High [CVE-2021-4034] Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

Local Privilege Escalation Vulnerability in Polkit's pkexec Utility

CVE-2021-4034
Unclassified
Jan 29, 2022
High8.1QNAP

High [CVE-2021-38692] QTS: stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard.

A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Guard 2.1.3.0 (2021/12/06) and later

CVE-2021-38692
QTSQuTS heroSurveillance (QVR)
Jan 14, 2022
High8.1QNAP

High [CVE-2021-38682] QTS: stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard.

A stack buffer overflow vulnerability has been reported to affect QNAP device running QVR Elite, QVR Pro, QVR Guard. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QVR Elite, QVR Pro, QVR Guard: QuTS hero h5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QuTS hero h4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 5.0.0: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Elite 2.1.4.0 (2021/12/06) and later QTS 4.5.4: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 5.0.0: QVR Pro 2.1.3.0 (2021/12/06) and later QTS 4.5.4: QVR Guard 2.1.3.0 and later QTS 5.0.0: QVR Guard 2.1.3.0 and later

CVE-2021-38682
QTSQuTS heroSurveillance (QVR)
Jan 14, 2022
High7.8Check Point

High [CVE-2021-30360] Users have access to the directory where the installation repair occurs.

Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote Access Client privileges.

CVE-2021-30360
Unclassified
Jan 10, 2022
High7.1QNAP

High [CVE-2021-38688] improper authentication vulnerability has been reported to affect Android App Qfile.

An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and later

CVE-2021-38688
Unclassified
Dec 29, 2021
High8.1QNAP

High [CVE-2021-38687] QTS: stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station.

A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS 5.0.0 (64 bit): Surveillance Station 5.2.0.4.2 ( 2021/10/26 ) and later QTS 5.0.0 (32 bit): Surveillance Station 5.2.0.3.2 ( 2021/10/26 ) and later QTS 4.3.6 (64 bit): Surveillance Station 5.1.5.4.6 ( 2021/10/26 ) and later QTS 4.3.6 (32 bit): Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later QTS 4.3.3: Surveillance Station 5.1.5.3.6 ( 2021/10/26 ) and later

CVE-2021-38687
QTS
Dec 29, 2021
High7.2Check Point

High [CVE-2021-30358] Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables

Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent.

CVE-2021-30358
Unclassified
Oct 19, 2021
High7.5F5

High [CVE-2020-5862 +1] On BIG-IP versions 15.1.0.4 through 15.1.3

On BIG-IP versions 15.1.0.4 through 15.1.3, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP on Amazon Web Services (AWS) systems, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This is due to an incomplete fix for CVE-2020-5862. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2020-5862CVE-2021-23051
BIG-IP
Sep 14, 2021
High8.6Check Point

High [CVE-2021-30355] Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to…

Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.

CVE-2021-30355
Unclassified
Sep 1, 2021