Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.4QNAP

Medium [CVE-2023-51367] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2023-51367
QTSQuTS hero
Sep 6, 2024
Medium4.3QNAP

Medium [CVE-2023-50366] QTS: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2023-50366
QTSQuTS hero
Sep 6, 2024
Medium4.3QNAP

Medium [CVE-2023-45038] Music Station: improper authentication vulnerability has been reported to affect Music Station.

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version: Music Station 5.4.0 and later

CVE-2023-45038
Applications
Sep 6, 2024
Medium6.6QNAP

Medium [CVE-2023-34979] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.5.4.2790 build 20240605 and later QuTS hero h4.5.4.2790 build 20240606 and later

CVE-2023-34979
QTSQuTS hero
Sep 6, 2024
Medium6.7QNAP

Medium [CVE-2022-27592] QVR: unquoted search path or element vulnerability has been reported to affect QVR Smart Client.

An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to execute unauthorized code or commands via unspecified vectors. We have already fixed the vulnerability in the following version: Windows 10 SP1, Windows 11, Mac OS, and Mac M1: QVR Smart Client 2.4.0.0570 and later

CVE-2022-27592
Surveillance (QVR)
Sep 6, 2024
Medium4.9F5

Medium [CVE-2024-7634] NGINX Agent's "config_dirs" restriction feature

NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

CVE-2024-7634
NGINX
Aug 22, 2024
Medium4.7F5

Medium [CVE-2024-7347] NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might

NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-7347
NGINX
Aug 14, 2024
Medium4.3F5

Medium [CVE-2024-41723] BIG-IP: Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names.

Undisclosed requests to BIG-IP iControl REST can lead to information leak of user account names. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-41723
BIG-IP
Aug 14, 2024
Medium4.2F5

Medium [CVE-2024-41719] When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged…

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-41719
BIG-IPBIG-IP Next
Aug 14, 2024
Medium5.9F5

Medium [CVE-2024-41164] When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions…

When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-41164
Unclassified
Aug 14, 2024
Medium5.3F5

Medium [CVE-2024-37028] BIG-IP Next: BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in.

BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-37028
BIG-IPBIG-IP Next
Aug 14, 2024
Medium4.2QNAP

Medium [CVE-2024-32765] QTS: vulnerability has been reported to affect Network & Virtual Switch.

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and execute certain functions via unspecified vectors. We have already fixed the vulnerability in the following versions: QTS 5.1.8.2823 build 20240712 and later Affected products named by the advisory: QuTS hero.

CVE-2024-32765
QTSQuTS hero
Aug 12, 2024
Medium5.8Aruba

Medium [CVE-2024-5486] vulnerability exists in ClearPass Policy Manager

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by ClearPass Policy Manager

CVE-2024-5486
ClearPassClearPass Policy Manager
Jul 30, 2024
Medium6.8Aruba

Medium [CVE-2024-41136] authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line…

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

CVE-2024-41136
EdgeConnect SD-WAN
Jul 24, 2024
Medium6.1Aruba

Medium [CVE-2024-22444] vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.

CVE-2024-22444
EdgeConnect SD-WAN
Jul 24, 2024
Medium5.3Splunk

Medium [CVE-2024-36996] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user exists on the instance by deciphering the error response that they would likely receive from the instance when they attempt to log in. This disclosure could then lead to additional brute-force password-guessing attacks. This vulnerability would require that the Splunk platform instance uses the Security Assertion Markup Language (SAML) authentication scheme.

CVE-2024-36996
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium5.4Splunk

Medium [CVE-2024-36995] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items.

CVE-2024-36995
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium5.4Splunk

Medium [CVE-2024-36994] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View and Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.

CVE-2024-36994
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium5.4Splunk

Medium [CVE-2024-36993] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a Splunk Web Bulletin Messages that could result in execution of unauthorized JavaScript code in the browser of a user.

CVE-2024-36993
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium5.4Splunk

Medium [CVE-2024-36992] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a View that could result in execution of unauthorized JavaScript code in the browser of a user. The “url” parameter of the Dashboard element does not have proper input validation to reject invalid URLs, which could lead to a Persistent Cross-site Scripting (XSS) exploit.

CVE-2024-36992
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024