Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.7QNAP

Medium [CVE-2021-44053] QTS: cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.0.1986 build 20220324 and later QuTS hero h5.0.0.1986 build 20220324 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTScloud c5.0.1.1949 and later

CVE-2021-44053
QTSQuTS hero
May 5, 2022
Medium6.5QNAP

Medium [CVE-2021-44052] QTS: improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running…

An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, and QTS. If exploited, this vulnerability allows remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, and QTS: QuTScloud c5.0.1.1998 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTS hero h5.0.0.1986 build 20220324 and later QTS 4.3.4.1976 build 20220303 and later QTS 4.3.3.1945 build 20220303 and later QTS 4.2.6 build 20220304 and later QTS 4.3.6.1965 build 20220302 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later

CVE-2021-44052
QTSQuTS hero
May 5, 2022
Medium5.3QNAP

Medium [CVE-2021-38693] path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance

A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appliance: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and later

CVE-2021-38693
QTSQuTS heroSurveillance (QVR)
May 5, 2022
Medium6.1pfSense

Medium [CVE-2021-20729] Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense…

Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.

CVE-2021-20729
pfSense PluspfSense CE
Mar 31, 2022
Medium6.5Proxmox

Medium [CVE-2022-28142 +1] Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with…

Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.

CVE-2022-28142CVE-2022-28144
Unclassified
Mar 29, 2022
Medium6.5Proxmox

Medium [CVE-2022-28142 +1] cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier

A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connect to an attacker-specified host using attacker-specified username and password (perform a connection test), disable SSL/TLS validation for the entire Jenkins controller JVM as part of the connection test (see CVE-2022-28142), and test a rollback with attacker-specified parameters.

CVE-2022-28142CVE-2022-28143
Unclassified
Mar 29, 2022
Medium6.5Proxmox

Medium [CVE-2022-28141] Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the…

Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

CVE-2022-28141
Unclassified
Mar 29, 2022
Medium5.3Sophos

Medium [CVE-2022-0331] Sophos Firewall: information disclosure vulnerability in Webadmin

An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.

CVE-2022-0331
Sophos Firewall (XGS/SFOS)
Mar 29, 2022
Medium6.1Sophos

Medium [CVE-2021-36809] local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially…

A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.

CVE-2021-36809
Unclassified
Mar 8, 2022
Medium5.3QNAP

Medium [CVE-2021-34361] QTS: cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVE-2021-34361
QTS
Feb 25, 2022
Medium6.5QNAP

Medium [CVE-2021-38679] QNAP NAS: improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server.

An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.22 and later

CVE-2021-38679
Unclassified
Feb 11, 2022
Medium5.4F5

Medium [CVE-2022-23008] On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2022-23008
NGINX
Jan 25, 2022
Medium6.1QNAP

Medium [CVE-2021-38678] open redirect vulnerability has been reported to affect QNAP device running QcalAgent.

An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later

CVE-2021-38678
Unclassified
Jan 14, 2022
Medium5.3QNAP

Medium [CVE-2021-38677] cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later

CVE-2021-38677
Unclassified
Jan 14, 2022
Medium4.2QNAP

Medium [CVE-2021-38674] QTS: cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud.

A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QuTS hero h4.5.4.1771 build 20210825 and later QTS 4.5.4.1787 build 20210910 and later QuTScloud c4.5.7.1864 and later

CVE-2021-38674
QTSQuTS hero
Jan 7, 2022
Medium5.3QNAP

Medium [CVE-2021-38680] cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server.

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Kazoo Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Kazoo Server: Kazoo Server 4.11.20 and later

CVE-2021-38680
Unclassified
Dec 29, 2021
Medium6.0Sophos

Medium [CVE-2021-25271] local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318

A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

CVE-2021-25271
Unclassified
Oct 8, 2021
Medium6.7Sophos

Medium [CVE-2021-25270] local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

CVE-2021-25270
Unclassified
Oct 8, 2021
Medium6.5F5

Medium [CVE-2021-23043] On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability…

On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to access arbitrary files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2021-23043
BIG-IP
Sep 14, 2021
Medium4.8Sophos

Medium [CVE-2021-25273] Sophos UTM: Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.

Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.

CVE-2021-25273
Sophos UTM
Jul 29, 2021