Latest CVE Feed
-
7.8
HIGHCVE-2024-49514
Photoshop Desktop versions 24.7.3, 25.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interac... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-49369
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an ... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
5.3
MEDIUMCVE-2024-30133
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.1
CRITICALCVE-2024-11006
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code exe... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
9.1
CRITICALCVE-2024-11005
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code exe... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
6.1
MEDIUMCVE-2024-11004
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
7.3
HIGHCVE-2024-10945
A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installa... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.4
HIGHCVE-2024-10944
A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permissions and exists due to improper input validation resulting in the possibility of a malicious Updated Agent being deployed.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.1
CRITICALCVE-2024-10943
An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information requ... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
8.6
HIGHCVE-2024-10923
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ ALM Octane Management allows Stored XSS. The vulnerability could result in a remote code execution attack. This issue affects ALM Octa... Read more
Affected Products : alm_octane- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2024-9420
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution... Read more
- Published: Nov. 12, 2024
- Modified: Mar. 13, 2025
-
7.5
HIGHCVE-2024-8495
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
9.8
CRITICALCVE-2024-52297
Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicConfiguratioDTO publicly exposed to users. This vulnerability is fixed in v3.81.2.... Read more
Affected Products : tolgee- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
6.5
MEDIUMCVE-2024-52296
libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
7.5
HIGHCVE-2024-50331
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-50330
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Apr. 23, 2025
-
8.8
HIGHCVE-2024-50329
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50328
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50327
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-50326
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024