Latest CVE Feed
-
8.7
HIGHCVE-2024-7939
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 13, 2024
-
8.7
HIGHCVE-2024-7932
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more
- Published: Sep. 02, 2024
- Modified: Sep. 13, 2024
-
9.1
CRITICALCVE-2024-34785
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-34783
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-34779
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32848
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32846
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32845
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32843
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32842
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
9.1
CRITICALCVE-2024-32840
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
10.0
CRITICALCVE-2024-29847
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 12, 2024
- Modified: Sep. 12, 2024
-
8.8
HIGHCVE-2024-8322
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
6.7
MEDIUMCVE-2024-8441
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
8.6
HIGHCVE-2024-8321
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
5.3
MEDIUMCVE-2024-8320
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
9.8
CRITICALCVE-2024-8191
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Sep. 10, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43783
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service ... Read more
- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
7.5
HIGHCVE-2024-43414
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and... Read more
Affected Products : apollo_router apollo_helms-charts_router apollo-router apollo_gateway apollo_query-planner- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024
-
6.4
MEDIUMCVE-2024-7304
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : ninja_tables- Published: Aug. 27, 2024
- Modified: Sep. 12, 2024