Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.1

    CRITICAL
    CVE-2024-32842

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32840

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 10.0

    CRITICAL
    CVE-2024-29847

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-8322

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 6.7

    MEDIUM
    CVE-2024-8441

    An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 8.6

    HIGH
    CVE-2024-8321

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 5.3

    MEDIUM
    CVE-2024-8320

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-8191

    SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-43783

    The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service ... Read more

    • Published: Aug. 27, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-43414

    Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and... Read more

    • Published: Aug. 27, 2024
    • Modified: Sep. 12, 2024
  • 6.4

    MEDIUM
    CVE-2024-7304

    The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it pos... Read more

    Affected Products : ninja_tables
    • Published: Aug. 27, 2024
    • Modified: Sep. 12, 2024
  • 6.4

    MEDIUM
    CVE-2024-6804

    The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more

    Affected Products : jeg_elementor_kit
    • Published: Aug. 27, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-43325

    Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.... Read more

    Affected Products : dark_mode_for_wp_dashboard
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 4.3

    MEDIUM
    CVE-2024-43316

    Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.... Read more

    Affected Products : stripe_payments_for_woocommerce
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-37930

    Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.... Read more

    Affected Products : smartmag
    • Published: Aug. 12, 2024
    • Modified: Sep. 12, 2024
  • 5.4

    MEDIUM
    CVE-2024-43299

    Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Team SpeedyCache.This issue affects SpeedyCache: from n/a through 1.1.8.... Read more

    Affected Products : speedycache
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-43129

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.... Read more

    Affected Products : betterdocs
    • Published: Aug. 13, 2024
    • Modified: Sep. 12, 2024
  • 4.3

    MEDIUM
    CVE-2024-43295

    Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.... Read more

    Affected Products : wp_data_access
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-43287

    Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82.... Read more

    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
  • 4.3

    MEDIUM
    CVE-2024-43269

    Cross-Site Request Forgery (CSRF) vulnerability in WPBackItUp Backup and Restore WordPress.This issue affects Backup and Restore WordPress: from n/a through 1.50.... Read more

    Affected Products : backup_and_restore_wordpress
    • Published: Aug. 26, 2024
    • Modified: Sep. 12, 2024
Showing 20 of 292759 Results