Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.3QNAP

Medium [CVE-2024-32770] Photo Station: cross-site scripting (XSS) vulnerability has been reported to affect Photo Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later

CVE-2024-32770
Applications
Nov 22, 2024
Medium4.0Fortinet

Medium [CVE-2023-50176] session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link

A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiOS 7.2.0 through 7.2.7, FortiOS 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

CVE-2023-50176
FortiGateFirewallFortiOS
Nov 12, 2024
Medium5.4F5

Medium [CVE-2024-10318] session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at…

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.

CVE-2024-10318
NGINX
Nov 6, 2024
Medium6.8Aruba

Medium [CVE-2024-47464] AOS-10: authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10.

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to a remote unauthorized access to files.

CVE-2024-47464
AOS-10Instant APWireless & ControllersInstant
Nov 5, 2024
Medium4.8pfSense

Medium [CVE-2024-46538] cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

CVE-2024-46538
Unclassified
Oct 22, 2024
Medium6.8F5

Medium [CVE-2024-47139] stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility

A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-47139
BIG-IQ
Oct 16, 2024
Medium5.4Splunk

Medium [CVE-2024-45741] In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a…

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom configuration file that the "api.uri" parameter from the "/manager/search/apps/local" endpoint in Splunk Web calls. This could result in execution of unauthorized JavaScript code in the browser of a user.

CVE-2024-45741
Splunk EnterpriseSplunk Cloud Platform
Oct 14, 2024
Medium5.4Splunk

Medium [CVE-2024-45740] In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user…

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through Scheduled Views that could result in execution of unauthorized JavaScript code in the browser of a user.

CVE-2024-45740
Splunk EnterpriseSplunk Cloud Platform
Oct 14, 2024
Medium4.9Splunk

Medium [CVE-2024-45739] In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local…

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at the DEBUG logging level.

CVE-2024-45739
Splunk Enterprise
Oct 14, 2024
Medium4.9Splunk

Medium [CVE-2024-45738] In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the…

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG logging level.

CVE-2024-45738
Splunk Enterprise
Oct 14, 2024
Medium4.3Splunk

Medium [CVE-2024-45737] In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and…

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).

CVE-2024-45737
Splunk EnterpriseSplunk Cloud Platform
Oct 14, 2024
Medium6.5Splunk

Medium [CVE-2024-45736] In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204…

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a Field Transformation which could crash the Splunk daemon (splunkd).

CVE-2024-45736
Splunk EnterpriseSplunk Cloud Platform
Oct 14, 2024
Medium4.3Splunk

Medium [CVE-2024-45735] In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below…

In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key Value Store (KV Store) deployment configuration and public/private keys in the Splunk Secure Gateway App.

CVE-2024-45735
Splunk EnterpriseSplunk Cloud Platform
Oct 14, 2024
Medium4.3Splunk

Medium [CVE-2024-45734] In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk…

In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. The images on the machine could be exposed by exporting the dashboard as a PDF, using the local image path in the img tag in the source extensible markup language (XML) code for the Splunk classic dashboard.

CVE-2024-45734
Splunk Enterprise
Oct 14, 2024
Medium6.6Ubiquiti

Medium [CVE-2024-44540] Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

CVE-2024-44540
UISP / airMAX
Sep 23, 2024
Medium5.4QNAP

Medium [CVE-2024-38640] cross-site scripting (XSS) vulnerability has been reported to affect Download Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later

CVE-2024-38640
Unclassified
Sep 6, 2024
Medium6.3QNAP

Medium [CVE-2024-27126] cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3.

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later

CVE-2024-27126
Unclassified
Sep 6, 2024
Medium4.7QNAP

Medium [CVE-2024-21906] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21906
QTSQuTS hero
Sep 6, 2024
Medium5.9QNAP

Medium [CVE-2024-21904] QTS: path traversal vulnerability has been reported to affect several QNAP operating system versions.

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21904
QTSQuTS hero
Sep 6, 2024
Medium6.6QNAP

Medium [CVE-2024-21903] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2024-21903
QTSQuTS hero
Sep 6, 2024