Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.8Splunk

Medium [CVE-2023-46213] In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can

In Splunk Enterprise versions below 9.0.7 and 9.1.2, ineffective escaping in the “Show syntax Highlighted” feature can result in the execution of unauthorized code in a user’s web browser.

CVE-2023-46213
Splunk Enterprise
Nov 16, 2023
Medium5.4pfSense

Medium [CVE-2023-42327] Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

CVE-2023-42327
Unclassified
Nov 14, 2023
Medium5.4pfSense

Medium [CVE-2023-42325] Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

CVE-2023-42325
Unclassified
Nov 14, 2023
Medium4.7QNAP

Medium [CVE-2023-23367] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build 20230421 and later QuTScloud c5.1.0.2498 and later Affected products named by the advisory: QuTS hero.

CVE-2023-23367
QTSQuTS hero
Nov 10, 2023
Medium4.3QNAP

Medium [CVE-2023-39301] QTS: server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions.

A server-side request forgery (SSRF) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to read application data via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2514 build 20230906 and later QTS 5.1.1.2491 build 20230815 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.1.2488 build 20230812 and later QuTScloud c5.1.0.2498 and later

CVE-2023-39301
QTSQuTS hero
Nov 3, 2023
Medium4.6QNAP

Medium [CVE-2023-34977] Video Station: cross-site scripting (XSS) vulnerability has been reported to affect Video Station.

A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

CVE-2023-34977
Applications
Oct 13, 2023
Medium6.6QNAP

Medium [CVE-2023-34975] QTS: OS command injection vulnerability has been reported to affect several QNAP operating system versions.

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h4.5.4.2626 build 20231225 and later QTS 4.5.4.2627 build 20231225 and later

CVE-2023-34975
QTSQuTS hero
Oct 13, 2023
Medium6.6QNAP

Medium [CVE-2023-32976] OS command injection vulnerability has been reported to affect Container Station.

An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Container Station 2.6.7.44 and later

CVE-2023-32976
Unclassified
Oct 13, 2023
Medium4.9QNAP

Medium [CVE-2023-32970] QTS: NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions.

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch a denial-of-service (DoS) attack via a network. QES is not affected. We have already fixed the vulnerability in the following versions: QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h5.1.0.2453 build 20230708 and later QuTS hero h4.5.4.2476 build 20230728 and later QuTScloud c5.1.0.2498 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later

CVE-2023-32970
QTSQuTS hero
Oct 13, 2023
Medium4.4F5

Medium [CVE-2023-45219] Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may

Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-45219
BIG-IP
Oct 10, 2023
Medium5.5F5

Medium [CVE-2023-43485] When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log

When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-43485
BIG-IPBIG-IQ
Oct 10, 2023
Medium4.3F5

Medium [CVE-2023-41964] BIG-IP: The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.

The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41964
BIG-IPBIG-IQ
Oct 10, 2023
Medium5.5F5

Medium [CVE-2023-41253] When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the…

When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-41253
BIG-IP
Oct 10, 2023
Medium4.4F5

Medium [CVE-2023-39447] BIG-IP: When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log.

When BIG-IP APM Guided Configurations are configured, undisclosed sensitive information may be logged in restnoded log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2023-39447
BIG-IP
Oct 10, 2023
Medium5.2QNAP

Medium [CVE-2023-23371] cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client.

A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.2.0.0823 and later

CVE-2023-23371
Unclassified
Oct 6, 2023
Medium6.7QNAP

Medium [CVE-2023-23370] insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client.

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors. We have already fixed the vulnerability in the following version: QVPN Windows 2.1.0.0518 and later

CVE-2023-23370
Unclassified
Oct 6, 2023
Medium6.8F5

Medium [CVE-2023-43125] BIG-IP: BIG-IP APM clients may send IP traffic outside of the VPN tunnel.

BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2023-43125
BIG-IP
Sep 27, 2023
Medium6.7QNAP

Medium [CVE-2022-27599] QVR: insertion of sensitive information into Log file vulnerability has been reported to affect product.

An insertion of sensitive information into Log file vulnerability has been reported to affect product. If exploited, the vulnerability possibly provides local authenticated administrators with an additional, less-protected path to acquiring the information via unspecified vectors. We have already fixed the vulnerability in the following version: Windows 10 SP1, Windows 11, Mac OS, and Mac M1: QVR Pro Client 2.3.0.0420 and later

CVE-2022-27599
Surveillance (QVR)
Sep 8, 2023
Medium6.5Splunk

Medium [CVE-2023-40594] In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker

In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.

CVE-2023-40594
Splunk Enterprise
Aug 30, 2023
Medium6.3Splunk

Medium [CVE-2023-40593] In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the `/saml/acs` REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.

CVE-2023-40593
Splunk Enterprise
Aug 30, 2023