|
310551
|
7.2 |
HIGH
Network
|
ivanti
|
endpoint_manager_cloud_services_appliance
|
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
|
CWE-22
Path Traversal
|
CVE-2024-9381
|
2024-10-16 22:30 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310552
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
|
CWE-22
Path Traversal
|
CVE-2024-47011
|
2024-10-16 22:28 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310553
|
9.8 |
CRITICAL
Network
|
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
|
CWE-22
Path Traversal
|
CVE-2024-47010
|
2024-10-16 22:28 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310554
|
8.8 |
HIGH
Network
|
adobe
|
commerce magento commerce_b2b
|
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged a…
|
NVD-CWE-noinfo
|
CVE-2024-45148
|
2024-10-16 22:27 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310555
|
9.8 |
CRITICAL
Network
|
ivanti
|
avalanche
|
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
|
CWE-22
Path Traversal
|
CVE-2024-47009
|
2024-10-16 22:26 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310556
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-47008
|
2024-10-16 22:24 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310557
|
7.5 |
HIGH
Network
|
ivanti
|
avalanche
|
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-47007
|
2024-10-16 22:23 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310558
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10_1507 windows_server_2016 windows_server_2022_23h2 windows_10_1809 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_10_22h2 windows…
|
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37983
|
2024-10-16 22:15 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310559
|
9.8 |
CRITICAL
Network
|
alisonic
|
sibylla_firmware
|
Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.
|
CWE-89
SQL Injection
|
CVE-2024-8630
|
2024-10-16 22:15 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310560
|
7.5 |
HIGH
Network
|
opentext
|
cx-e_voice
|
Path Traversal vulnerability discovered in OpenText™ CX-E Voice,
affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.
|
CWE-22
Path Traversal
|
CVE-2023-7260
|
2024-10-16 21:53 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|