Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium6.5Splunk

Medium [CVE-2024-36990] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk Enterprise, potentially causing a denial of service.

CVE-2024-36990
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium4.3Splunk

Medium [CVE-2024-36987] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the admin or power Splunk roles could upload a file with an arbitrary extension using the indexing/preview REST endpoint.

CVE-2024-36987
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium6.3Splunk

Medium [CVE-2024-36986] In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and…

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

CVE-2024-36986
Splunk EnterpriseSplunk Cloud Platform
Jul 1, 2024
Medium5.3F5

Medium [CVE-2024-35200] When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.

CVE-2024-35200
NGINX
May 29, 2024
Medium5.3F5

Medium [CVE-2024-34161] When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum…

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

CVE-2024-34161
NGINX
May 29, 2024
Medium6.5F5

Medium [CVE-2024-32760] When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.

CVE-2024-32760
NGINX
May 29, 2024
Medium4.8F5

Medium [CVE-2024-31079] When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.

CVE-2024-31079
NGINX
May 29, 2024
Medium6.4QNAP

Medium [CVE-2024-27129] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-27129
QTSQuTS hero
May 21, 2024
Medium6.4QNAP

Medium [CVE-2024-21902] QTS: incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system…

An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21902
QTSQuTS hero
May 21, 2024
Medium6.8F5

Medium [CVE-2024-33612] improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-33612
BIG-IPBIG-IP Next
May 8, 2024
Medium6.1F5

Medium [CVE-2024-33604] reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility

A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-33604
BIG-IP
May 8, 2024
Medium6.5F5

Medium [CVE-2024-32761] BIG-IP: Under certain conditions, a data leak

Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak occurs randomly and cannot be deliberately triggered. If it occurs, it may leak up to 64 bytes of non-contiguous randomized bytes. Under rare conditions, this may lead to a TMM restart, affecting availability. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-32761
BIG-IP
May 8, 2024
Medium5.9F5

Medium [CVE-2024-28889] When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along…

When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-28889
Unclassified
May 8, 2024
Medium4.4F5

Medium [CVE-2024-28132] Exposure of Sensitive Information vulnerability exists in the GSLB container, which may

Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-28132
Unclassified
May 8, 2024
Medium4.7F5

Medium [CVE-2024-27202] DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility

A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-27202
BIG-IP
May 8, 2024
Medium6.6QNAP

Medium [CVE-2023-47220] OS command injection vulnerability has been reported to affect Media Streaming add-on.

An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Media Streaming add-on 500.1.1.5 ( 2024/01/22 ) and later

CVE-2023-47220
Unclassified
May 3, 2024
Medium5.3Aruba

Medium [CVE-2024-33516] ArubaOS: unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed

An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the controller.

CVE-2024-33516
AOS-8 MobilityWireless & ControllersArubaOS
May 1, 2024
Medium6.7Check Point

Medium [CVE-2024-24912] local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10…

A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system.

CVE-2024-24912
Harmony (Endpoint/Mobile)
May 1, 2024
Medium6.5QNAP

Medium [CVE-2024-21905] QTS: integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions.

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2024-21905
QTSQuTS hero
Apr 26, 2024
Medium6.4QNAP

Medium [CVE-2023-50364] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.6.2722 build 20240402 and later QuTS hero h5.1.6.2734 build 20240414 and later

CVE-2023-50364
QTSQuTS hero
Apr 26, 2024