Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.5QNAP

Medium [CVE-2023-41283] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2023-41283
QTSQuTS hero
Feb 2, 2024
Medium5.5QNAP

Medium [CVE-2023-41280] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

CVE-2023-41280
QTSQuTS hero
Feb 2, 2024
Medium5.5QNAP

Medium [CVE-2023-41274] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

CVE-2023-41274
QTSQuTS hero
Feb 2, 2024
Medium5.5QNAP

Medium [CVE-2023-41273] QTS: heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions.

A heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.1.2.2534 build 20230927 and later QuTScloud c5.1.5.2651 and later

CVE-2023-41273
QTSQuTS hero
Feb 2, 2024
Medium5.3QNAP

Medium [CVE-2023-39303] QTS: improper authentication vulnerability has been reported to affect several QNAP operating system versions.

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2023-39303
QTSQuTS hero
Feb 2, 2024
Medium6.6QNAP

Medium [CVE-2023-39302] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later QuTScloud c5.1.5.2651 and later Affected products named by the advisory: QuTS hero.

CVE-2023-39302
QTSQuTS hero
Feb 2, 2024
Medium5.0QNAP

Medium [CVE-2023-32967] QTS: incorrect authorization vulnerability has been reported to affect several QNAP operating system versions.

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended access restrictions via a network. QTS 5.x, QuTS hero are not affected. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 4.5.4.2627 build 20231225 and later

CVE-2023-32967
QTSQuTS hero
Feb 2, 2024
Medium6.8Splunk

Medium [CVE-2023-46231] In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.

CVE-2023-46231
Unclassified
Jan 30, 2024
Medium4.3Splunk

Medium [CVE-2024-23677] In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in…

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

CVE-2024-23677
Splunk Enterprise
Jan 22, 2024
Medium4.6Splunk

Medium [CVE-2024-23676] In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have permission to view. This vulnerability requires user interaction from a high-privileged user to exploit.

CVE-2024-23676
Unclassified
Jan 22, 2024
Medium6.5Splunk

Medium [CVE-2024-23675] In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for…

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application programming interface (API). This can potentially result in the deletion of KV Store collections.

CVE-2024-23675
Splunk Enterprise
Jan 22, 2024
Medium6.5Splunk

Medium [CVE-2024-22165] In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed investigation prevents the generation and rendering of the Investigations manager until it is deleted. The vulnerability requires an authenticated session and access to create an Investigation. It only affects the availability of the Investigations manager, but without the manager, the Investigations functionality becomes unusable for most users.

CVE-2024-22165
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024
Medium4.3Splunk

Medium [CVE-2024-22164] In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

CVE-2024-22164
Splunk EnterpriseES / ITSI / SOAR
Jan 9, 2024
Medium5.5QNAP

Medium [CVE-2023-47559] QuMagie: cross-site scripting (XSS) vulnerability has been reported to affect QuMagie.

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: QuMagie 2.2.1 and later

CVE-2023-47559
Applications
Jan 5, 2024
Medium6.3QNAP

Medium [CVE-2023-41289] OS command injection vulnerability has been reported to affect QcalAgent.

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: QcalAgent 1.1.8 and later

CVE-2023-41289
Unclassified
Jan 5, 2024
Medium4.3QNAP

Medium [CVE-2023-41287] Video Station: SQL injection vulnerability has been reported to affect Video Station.

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later

CVE-2023-41287
Applications
Jan 5, 2024
Medium6.6QNAP

Medium [CVE-2023-39294] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build 20231110 and later Affected products named by the advisory: QuTS hero.

CVE-2023-39294
QTSQuTS hero
Jan 5, 2024
Medium4.9QNAP

Medium [CVE-2023-32975] QTS: buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.2.2533 build 20230926 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.2.2534 build 20230927 and later

CVE-2023-32975
QTSQuTS hero
Dec 8, 2023
Medium6.5QNAP

Medium [CVE-2023-23372] QTS: cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions.

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h4.5.4.2476 build 20230728 and later

CVE-2023-23372
QTSQuTS hero
Dec 8, 2023
Medium4.7Sophos

Medium [CVE-2021-36806] Sophos Email: reflected XSS vulnerability allows an open redirect

A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.

CVE-2021-36806
Unclassified
Nov 30, 2023