|
312551
|
8.8 |
HIGH
Network
|
ivanti
|
endpoint_manager
|
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
|
NVD-CWE-Other
|
CVE-2024-8322
|
2024-09-13 06:56 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312552
|
6.7 |
MEDIUM
Local
|
ivanti
|
endpoint_manager
|
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-8441
|
2024-09-13 06:53 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312553
|
8.6 |
HIGH
Network
|
ivanti
|
endpoint_manager
|
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8321
|
2024-09-13 06:53 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312554
|
5.3 |
MEDIUM
Network
|
ivanti
|
endpoint_manager
|
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-8320
|
2024-09-13 06:51 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312555
|
9.8 |
CRITICAL
Network
|
ivanti
|
endpoint_manager
|
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
|
CWE-89
SQL Injection
|
CVE-2024-8191
|
2024-09-13 06:50 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312556
|
7.5 |
HIGH
Network
|
apollographql
|
apollo-router apollo_helms-charts_router apollo_router
|
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-43783
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312557
|
7.5 |
HIGH
Network
|
apollographql
|
apollo_router apollo_helms-charts_router apollo-router apollo_query-planner apollo_gateway
|
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incre…
|
CWE-674
Uncontrolled Recursion
|
CVE-2024-43414
|
2024-09-13 06:33 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312558
|
5.4 |
MEDIUM
Network
|
wpmanageninja
|
ninja_tables
|
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7304
|
2024-09-13 06:32 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312559
|
5.4 |
MEDIUM
Network
|
jegtheme
|
jeg_elementor_kit
|
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and out…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6804
|
2024-09-13 06:31 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312560
|
8.8 |
HIGH
Network
|
naiches
|
dark_mode_for_wp_dashboard
|
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.
|
CWE-352
Origin Validation Error
|
CVE-2024-43325
|
2024-09-13 06:28 |
2024-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|