Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.4Splunk

Medium [CVE-2023-22942] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG)…

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, a cross-site request forgery in the Splunk Secure Gateway (SSG) app in the ‘kvstore_client’ REST endpoint lets a potential attacker update SSG KV store collections using an HTTP GET request.

CVE-2023-22942
Splunk Enterprise
Feb 14, 2023
Medium6.5Splunk

Medium [CVE-2023-22941] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field…

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, an improperly-formatted ‘INGEST_EVAL’ parameter in a Field Transformation crashes the Splunk daemon (splunkd).

CVE-2023-22941
Splunk Enterprise
Feb 14, 2023
Medium6.3Splunk

Medium [CVE-2023-22940] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL)…

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, aliases of the ‘collect’ search processing language (SPL) command, including ‘summaryindex’, ‘sumindex’, ‘stash’,’ mcollect’, and ‘meventcollect’, were not designated as safeguarded commands. The commands could potentially allow for the exposing of data to a summary index that unprivileged users could access. The vulnerability requires a higher privileged user to initiate a request within their browser, and only affects instances with Splunk Web enabled.

CVE-2023-22940
Splunk Enterprise
Feb 14, 2023
Medium4.3Splunk

Medium [CVE-2023-22938] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘sendemail’ REST API endpoint lets any authenticated user send an email as the Splunk instance. The endpoint is now restricted to the ‘splunk-system-user’ account on the local instance.

CVE-2023-22938
Splunk Enterprise
Feb 14, 2023
Medium4.3Splunk

Medium [CVE-2023-22937] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the lookup table upload feature let a user upload lookup tables with unnecessary filename extensions. Lookup table file extensions may now be one of the following only:.csv,.csv.gz,.kmz,.kml,.mmdb, or.mmdb.gzl.

CVE-2023-22937
Splunk Enterprise
Feb 14, 2023
Medium6.3Splunk

Medium [CVE-2023-22936] In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search

In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an additional vulnerability within the environment.

CVE-2023-22936
Splunk Enterprise
Feb 14, 2023
Medium4.3Splunk

Medium [CVE-2023-22931] In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource…

In Splunk Enterprise versions below 8.1.13 and 8.2.10, the ‘createrss’ external search command overwrites existing Resource Description Format Site Summary (RSS) feeds without verifying permissions. This feature has been deprecated and disabled by default.

CVE-2023-22931
Splunk Enterprise
Feb 14, 2023
Medium5.9Ubiquiti

Medium [CVE-2023-23119] The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X…

The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes Ubiquiti airFiber AF2X Radio firmware version 3.2.2 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.

CVE-2023-23119
UISP / airMAX
Feb 2, 2023
Medium4.3Sophos

Medium [CVE-2022-3711] Sophos Firewall: post-auth read-only SQL injection vulnerability

A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3711
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
Medium6.8Sophos

Medium [CVE-2022-3709] Sophos Firewall: stored XSS vulnerability

A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.

CVE-2022-3709
Sophos Firewall (XGS/SFOS)
Dec 1, 2022
Medium4.9Splunk

Medium [CVE-2022-43564] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule search reports can cause a denial of service through the use of specially crafted search macros.

CVE-2022-43564
Splunk Enterprise
Nov 4, 2022
Medium6.4Splunk

Medium [CVE-2022-43561] In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store arbitrary scripts that can lead to persistent cross-site scripting (XSS). The vulnerability affects instances with Splunk Web enabled.

CVE-2022-43561
Splunk Enterprise
Nov 3, 2022
Medium6.1pfSense

Medium [CVE-2022-42247] pfSense: pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.

pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

CVE-2022-42247
Unclassified
Oct 3, 2022
Medium5.5Splunk

Medium [CVE-2022-37439] In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the…

In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually removing the malformed file.

CVE-2022-37439
Splunk EnterpriseUniversal Forwarder
Aug 16, 2022
Medium5.3QNAP

Medium [CVE-2021-34360] QTS: cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server.

A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVE-2021-34360
QTSQuTS hero
May 26, 2022
Medium6.7Check Point

Medium [CVE-2021-30361] The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to…

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS.

CVE-2021-30361
Quantum Gateway / Gaia
May 11, 2022
Medium6.8Sophos

Medium [CVE-2021-25267] Sophos Firewall: Multiple XSS vulnerabilities in Webadmin

Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.

CVE-2021-25267
Sophos Firewall (XGS/SFOS)
May 5, 2022
Medium4.3F5

Medium [CVE-2022-1468] On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user…

On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl REST user with at least guest role privileges can cause processing delays to iControl REST requests via undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-1468
BIG-IP
May 5, 2022
Medium5.3QNAP

Medium [CVE-2021-44055] Video Station: missing authorization vulnerability has been reported to affect QNAP device running Video Station.

An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows remote attackers to access data or perform actions that they should not be allowed to perform. We have already fixed this vulnerability in the following versions of Video Station: Video Station 5.5.9 ( 2022/02/16 ) and later

CVE-2021-44055
Applications
May 5, 2022
Medium4.3QNAP

Medium [CVE-2021-44054] QTS: open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS.

An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero and QTS: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later

CVE-2021-44054
QTSQuTS hero
May 5, 2022