Latest CVE Feed
-
9.1
CRITICALCVE-2024-32846
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32845
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32843
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32842
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32840
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
10.0
CRITICALCVE-2024-29847
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-8322
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
6.7
MEDIUMCVE-2024-8441
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
8.6
HIGHCVE-2024-8321
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
5.3
MEDIUMCVE-2024-8320
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-8191
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43783
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service ... Read more
- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43414
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and... Read more
Affected Products : apollo_router apollo_helms-charts_router apollo-router apollo_gateway apollo_query-planner- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
6.4
MEDIUMCVE-2024-7304
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : ninja_tables- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
6.4
MEDIUMCVE-2024-6804
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a... Read more
Affected Products : jeg_elementor_kit- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43325
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.... Read more
Affected Products : dark_mode_for_wp_dashboard- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2024-43316
Cross-Site Request Forgery (CSRF) vulnerability in Checkout Plugins Stripe Payments For WooCommerce by Checkout.This issue affects Stripe Payments For WooCommerce by Checkout: from n/a through 1.9.1.... Read more
Affected Products : stripe_payments_for_woocommerce- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-37930
Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization vulnerability in ThemeSphere SmartMag allows Excavation, Accessing Functionality Not Properly Constrained by ACLs.This issue affects SmartMag: from n/a through 9.3.0.... Read more
Affected Products : smartmag- Published: Aug. 12, 2024
- Modified: Sep. 12, 2024
-
5.4
MEDIUMCVE-2024-43299
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Team SpeedyCache.This issue affects SpeedyCache: from n/a through 1.1.8.... Read more
Affected Products : speedycache- Published: Aug. 26, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-43129
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.... Read more
Affected Products : betterdocs- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024