Latest CVE Feed
-
7.2
HIGHCVE-2024-50324
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-50323
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-50322
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.... Read more
Affected Products : endpoint_manager- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50321
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50320
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50319
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50318
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-50317
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : avalanche- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
4.9
MEDIUMCVE-2024-47909
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-47907
A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : connect_secure- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
7.8
HIGHCVE-2024-47906
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 17, 2025
-
4.9
MEDIUMCVE-2024-47905
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 18, 2024
-
5.5
MEDIUMCVE-2024-47535
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded ... Read more
Affected Products : netty- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.0
CRITICALCVE-2024-43415
An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write ... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 13, 2024
-
9.1
CRITICALCVE-2024-11007
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code exe... Read more
- Published: Nov. 12, 2024
- Modified: Nov. 22, 2024
-
4.3
MEDIUMCVE-2024-10971
Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission.... Read more
Affected Products : devolutions_server- Published: Nov. 12, 2024
- Modified: Jun. 27, 2025
-
9.3
CRITICALCVE-2024-8074
Improper Privilege Management vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users.This issue affects Nomysem: before 13.10.2024.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2024-51566
The NVMe driver queue processing is vulernable to guest-induced infinite loops.... Read more
Affected Products : freebsd- Published: Nov. 12, 2024
- Modified: Nov. 26, 2024
-
6.5
MEDIUMCVE-2024-51565
The hda driver is vulnerable to a buffer over-read from a guest-controlled value.... Read more
Affected Products : freebsd- Published: Nov. 12, 2024
- Modified: Nov. 26, 2024
-
7.5
HIGHCVE-2024-51564
A guest can trigger an infinite loop in the hda audio driver.... Read more
Affected Products :- Published: Nov. 12, 2024
- Modified: Nov. 21, 2024