[NEW] [high] Splunk Splunk Enterprise: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Splunk Splunk Enterprise to bypass security measures, manipulate data, and disclose confidential information.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
An attacker can exploit multiple vulnerabilities in Splunk Splunk Enterprise to bypass security measures, manipulate data, and disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in F5 BIG-IP and BIG-IP Next to perform a Denial of Service attack.
A local attacker can exploit a vulnerability in Veeam Backup & Replication to gain administrator rights.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Developer Hub to bypass security measures, disclose information, or cause a Denial of Service.
A remote, anonymous attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a Denial of Service.
An attacker can exploit multiple vulnerabilities in Grub to execute arbitrary code, create a Denial-of-Service condition, manipulate data, bypass security measures, disclose confidential information, or cause unspecified impacts.
A local attacker can exploit these vulnerabilities to cause a Denial-of-Service condition or perform an unspecified attack.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to cause a Denial-of-Service condition or perform an unspecified attack.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack or cause unknown impacts.
A local attacker can exploit a vulnerability in the Red Hat OpenShift Container Platform to bypass security measures.
An attacker from an adjacent network can exploit a vulnerability in dhcpcd to conduct a denial of service attack.
A local attacker can exploit multiple vulnerabilities in Dell PowerScale OneFS to disclose information or escalate privileges.
An attacker can exploit multiple vulnerabilities in MongoDB to perform a Denial of Service attack and manipulate data.
An attacker can exploit multiple vulnerabilities in Google Chrome to conduct an unspecified attack, potentially including executing arbitrary code, causing a denial-of-service attack, bypassing security measures, and altering and disclosing data.
A remote, anonymous attacker can exploit a vulnerability in ImageMagick to conduct a denial of service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in n8n to perform SQL injection, bypass security measures, disclose sensitive information, manipulate data, or cause a Denial of Service condition.
A remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary code.
An attacker can exploit multiple vulnerabilities in dhcpcd to carry out a Denial of Service attack.
A local attacker can exploit a vulnerability in QEMU to disclose, modify information, or cause a Denial of Service.
A local attacker can exploit a vulnerability in QEMU to cause a denial-of-service state and potentially execute arbitrary code on the host.
A remote, anonymous attacker can exploit multiple vulnerabilities in ImageMagick to bypass security measures, cause a denial-of-service condition, or disclose confidential information.
A local attacker can exploit a vulnerability in QEMU to escalate their privileges and execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in Wazuh Manager to escalate their privileges.
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Red Hat OpenShift to execute arbitrary code, conduct a Denial of Service attack, manipulate files, and disclose information.
An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, manipulate data, perform an SQL injection attack, and conduct a cross-site scripting attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift Service Mesh to carry out a Denial of Service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in Keycloak to escalate privileges and bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in libpng to potentially execute arbitrary code, disclose confidential information, or cause a denial-of-service condition.
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Grafana to carry out a Denial of Service attack or gain elevated permissions.
A remote, anonymous attacker can exploit multiple vulnerabilities in Vaultwarden to gain user rights and disclose information.
A local attacker can exploit multiple vulnerabilities in ImageMagick to conduct a Denial of Service attack or disclose confidential information.
A remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD to disclose information or perform cross-site scripting attacks, potentially gaining administrator rights.
A remote, anonymous attacker can exploit a vulnerability in GNU libc to disclose information.
A remote, authenticated attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary code, manipulate data, disclose sensitive information, or cause a Denial of Service condition.
An attacker can exploit multiple vulnerabilities in Fortinet FortiSIEM to conduct a Cross-Site Scripting attack or execute code.
A remote, authenticated attacker can exploit a vulnerability in n8n to disclose information.
An attacker can exploit multiple vulnerabilities in various Microsoft Azure components to escalate privileges and conduct a Denial of Service attack.
TTSSH2 plugin of Tera Term provided by TeraTerm Project contains multiple vulnerabilities.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6390-1
A vulnerability has been discovered in Ruby on Rails. It allows an attacker to cause a remote indirect code injection (XSS).
Multiple vulnerabilities have been discovered in F5 products. Some of them allow an attacker to cause remote arbitrary code execution, a remote denial of service, and a breach of data confidentiality.
Multiple vulnerabilities have been discovered in Splunk products. Some of them allow an attacker to cause a breach of data confidentiality, a breach of data integrity, and a cross-site request forgery (CSRF).
A vulnerability has been discovered in ESET products. It allows an attacker to cause a denial of service.
Multiple vulnerabilities have been discovered in Cisco RoomOS. Some of them allow an attacker to cause a breach of data confidentiality, a security policy bypass, and an unspecified security issue by the vendor.
A vulnerability has been discovered in Traefik. It allows an attacker to cause a security policy bypass.