Latest CVE Feed
-
5.5
MEDIUMCVE-2025-47135
Dimension versions 4.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requir... Read more
- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Information Disclosure
-
7.3
HIGHCVE-2025-49536
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and g... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.4
HIGHCVE-2025-49538
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead to arbitrary file system read. An attacker can exploit this issue by injecting crafted XML or XPath queries to access unauthorized file... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: XML External Entity
-
7.1
HIGHCVE-2024-7572
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.... Read more
Affected Products : desktop_\&_server_management- Published: Dec. 10, 2024
- Modified: Jul. 11, 2025
-
7.8
HIGHCVE-2024-10630
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.... Read more
- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13172
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2024-13171
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-13170
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2024-13169
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13168
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2024-13164
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-13163
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
-
7.5
HIGHCVE-2024-13165
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13166
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13167
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.2
HIGHCVE-2024-13162
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6770
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution... Read more
Affected Products : endpoint_manager_mobile- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6771
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution... Read more
Affected Products : endpoint_manager_mobile- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-6970
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter ... Read more
Affected Products : events_manager- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-6975
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and out... Read more
Affected Products : events_manager- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting