Skip to content
VulniPulse

Complete feed

No mitigation yet

No fix, workaround or mitigation extracted yet

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium5.4pfSense

Medium [CVE-2020-19203] pfSense: authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of…

An authenticated Cross-Site Scripting (XSS) vulnerability was found in widgets/widgets/wake_on_lan_widget.php, a component of the pfSense software WebGUI, on version 2.4.4-p2 and earlier. The widget did not encode the descr (description) parameter of wake-on-LAN entries in its output, leading to a possible stored XSS.

CVE-2020-19203
Unclassified
Jul 12, 2021
Medium5.4pfSense

Medium [CVE-2020-19201] Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI…

A Stored Cross-Site Scripting (XSS) vulnerability was found in status_filter_reload.php, a page in the pfSense software WebGUI, on Netgate pfSense version 2.4.4-p2 and earlier. The page did not encode output from the filter reload process, and a stored XSS was possible via the descr (description) parameter on NAT rules.

CVE-2020-19201
Unclassified
Jul 12, 2021
Medium5.3Check Point

Medium [CVE-2021-30357] SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

CVE-2021-30357
Unclassified
Jun 8, 2021
Medium5.4pfSense

Medium [CVE-2020-26693] stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which

A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbitrary web scripts via exploitation of the load_balancer_monitor.php function.

CVE-2020-26693
Unclassified
Jun 1, 2021
Medium6.7Sophos

Medium [CVE-2021-25264] In multiple versions of Sophos Endpoint products for MacOS, a local attacker

In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.

CVE-2021-25264
Unclassified
May 17, 2021
Medium6.1pfSense

Medium [CVE-2021-27933] pfSense: pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

CVE-2021-27933
Unclassified
Apr 28, 2021
Medium5.3F5

Medium [CVE-2021-23007] On BIG-IP versions 14.1.4 and 16.0.1.1

On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclosed traffic, it may start dropping all fragmented IP traffic. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVE-2021-23007
BIG-IP
Mar 31, 2021
Medium6.1QNAP

Medium [CVE-2020-2502] Photo Station: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later

CVE-2020-2502
Applications
Feb 17, 2021
Medium4.8F5

Medium [CVE-2021-22981] On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that…

On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiation that is mitigated by the Extended Master Secret (EMS) extension defined in RFC 7627. TLS connections that do not use EMS are vulnerable to man-in-the-middle attacks during renegotiation. Note: Software versions which have reached End of Software Development (EoSD) are not evaluated.

CVE-2021-22981
BIG-IP
Feb 12, 2021
Medium5.8QNAP

Medium [CVE-2020-2504] If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station.

If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

CVE-2020-2504
Unclassified
Dec 24, 2020
Medium6.3QNAP

Medium [CVE-2020-2499] hard-coded password vulnerability has been reported to affect earlier versions of QES.

A hard-coded password vulnerability has been reported to affect earlier versions of QES. If exploited, this vulnerability could allow attackers to log in with a hard-coded password. QNAP has already fixed the issue in QES 2.1.1 Build 20200515 and later.

CVE-2020-2499
Unclassified
Dec 24, 2020
Medium6.1QNAP

Medium [CVE-2020-2498] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in certificate configuration. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2498
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2497] QTS: If exploited, this cross-site scripting vulnerability could

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in System Connection Logs. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2497
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2496] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QANP have already fixed these vulnerabilities in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later QTS 4.3.6.1333 build 20200608 and later QTS 4.3.4.1368 build 20200703 and later QTS 4.3.3.1315 build 20200611 and later QTS 4.2.6 build 20200611 and later

CVE-2020-2496
QTSQuTS hero
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2494] QTS: This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

CVE-2020-2494
QTSQuTS heroApplications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2493] Multimedia Console: This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Multimedia Console allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in Multimedia Console 1.1.5 and later.

CVE-2020-2493
Applications
Dec 10, 2020
Medium6.1QNAP

Medium [CVE-2020-2491] QTS: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later

CVE-2020-2491
QTSApplications
Dec 10, 2020
Medium6.1QNAP Exploited CISA KEV

Medium [CVE-2018-19953] QTS: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CVE-2018-19953
QTS
Oct 28, 2020
Medium4.3QNAP

Medium [CVE-2018-19947] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19947
Unclassified
Sep 11, 2020
Medium4.2QNAP

Medium [CVE-2018-19946] Helpdesk: The vulnerability have been reported to affect earlier versions of Helpdesk.

The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.

CVE-2018-19946
Unclassified
Sep 11, 2020