|
251831
|
9.8 |
CRITICAL
Network
|
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
|
CWE-22
Path Traversal
|
CVE-2024-47010
|
2024-10-16 22:28 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251832
|
8.8 |
HIGH
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged a…
|
NVD-CWE-noinfo
|
CVE-2024-45148
|
2024-10-16 22:27 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251833
|
9.8 |
CRITICAL
Network
|
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
|
CWE-22
Path Traversal
|
CVE-2024-47009
|
2024-10-16 22:26 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251834
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-47008
|
2024-10-16 22:24 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251835
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-47007
|
2024-10-16 22:23 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251836
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_10_22h2 windows…
|
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37983
|
2024-10-16 22:15 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251837
|
9.8 |
CRITICAL
Network
|
alisonic
|
sibylla_firmware
|
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
|
CWE-89
SQL Injection
|
CVE-2024-8630
|
2024-10-16 22:15 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251838
|
7.5 |
HIGH
Network
|
opentext
|
cx-e_voice
|
Path Traversal vulnerability discovered in OpenText™ CX-E Voice,
affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
|
CWE-22
Path Traversal
|
CVE-2023-7260
|
2024-10-16 21:53 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251839
|
- |
|
-
|
-
|
There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windows installs. A local "m2cuser" was greated with administrator privileges. This …
|
-
|
CVE-2024-9858
|
2024-10-16 18:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251840
|
- |
|
-
|
-
|
A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead…
|
CWE-1270
Generation of Incorrect Security Tokens
|
CVE-2023-32188
|
2024-10-16 18:15 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|